Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks
watchTowr warns two unpatched Citrix NetScaler RCE zero-days are allegedly exploited, without Citrix confirmation.
watchTowr says two undisclosed Citrix NetScaler remote code execution flaws are unpatched zero-days found during forensic work and allegedly exploited in the wild. Citrix had not issued CVE identifiers, affected-build details, indicators, or an advisory at publication time. The report is separate from Citrix’s August bulletin on CVE-2026-19490, a CVSS 9.3 authentication bypass already added to CISA’s KEV catalog, and CVE-2026-19489, an 8.8 memory-overflow issue. Until clarification, defenders are advised to inventory exposed appliances, restrict management access, preserve logs, and isolate systems if residual risk is unacceptable.