Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks
watchTowr warns two unpatched Citrix NetScaler RCE zero-days are allegedly exploited, without Citrix confirmation.
watchTowr says two undisclosed Citrix NetScaler remote code execution flaws are unpatched zero-days found during forensic work and allegedly exploited in the wild. Citrix had not issued CVE identifiers, affected-build details, indicators, or an advisory at publication time. The report is separate from Citrix’s August bulletin on CVE-2026-19490, a CVSS 9.3 authentication bypass already added to CISA’s KEV catalog, and CVE-2026-19489, an 8.8 memory-overflow issue. Until clarification, defenders are advised to inventory exposed appliances, restrict management access, preserve logs, and isolate systems if residual risk is unacceptable.
- watchTowr reports two unpatched NetScaler RCE zero-days found in forensic investigations.
- Citrix has published no CVE, affected builds, indicators, or advisory for the new flaws.
- Reports are distinct from August flaws CVE-2026-19490 and CVE-2026-19489.
- CVE-2026-19490, an auth bypass rated 9.3, is already in CISA’s KEV catalog.
- Defenders are urged to inventory exposure, preserve evidence, and isolate appliances if needed.
Vulnerabilities mentionedAll →
- CVE-2026-194898.8<1%Unauthenticated Buffer Overflow in Citrix NetScaler ADC and NetScaler Gatewaypublished · Citrix NetScaler ADC (formerly Citrix ADC)
- CVE-2026-194909.37%Remote Authentication Bypass in Citrix NetScaler ADC and NetScaler Gateway
Full article639 words · extracted from cybersecuritynews.com · click to collapse
Citrix NetScaler administrators are confronting reports of two undisclosed remote code execution vulnerabilities allegedly exploited in real-world attacks.
watchTowr said the flaws are unpatched zero-days, were identified during forensic investigations, and that Citrix communications and fixes are expected early next week. However, Citrix had not published technical details, CVE identifiers, affected builds, indicators of compromise, or an advisory for these reported flaws at the time of writing, leaving defenders to make high-impact decisions with limited verified information.
The warning began with reports that multiple unpatched NetScaler RCE vulnerabilities were circulating in the wild. watchTowr described the intelligence as credible and later stated that two separate vulnerabilities can enable remote code execution.
The company has not publicly disclosed exploitation paths, prerequisites, payloads, or forensic artifacts, making independent validation difficult. Treat the claims as a serious warning, not yet a fully vendor-confirmed disclosure.
— watchTowr (@watchtowrcyber) September 26, 2026We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the information is credible.
watchTowr Platform clients have been made aware of their Citrix NetScaler exposure. pic.twitter.com/Wufu7eMOcm
Some organizations reportedly responded by shutting down internet-exposed NetScaler appliances. Such action can interrupt VPN access, application delivery, authentication, and other critical services, yet edge appliances occupy a privileged position at the network boundary.
If defenders cannot patch or reliably mitigate a potentially exploitable RCE flaw, temporarily removing exposed systems from service may be the safer decision, particularly for sensitive environments.
The emerging alert must not be confused with Citrix’s August 19 bulletin covering CVE-2026-19490 and CVE-2026-19489. CVE-2026-19490 is a critical authentication-bypass flaw rated 9.3 under CVSS v4.0; it affects certain customer-managed NetScaler Gateway and AAA virtual-server configurations.
CVE-2026-19489, rated 8.8, is a memory-overflow issue requiring SIP ALG on a Large Scale NAT group and can cause unpredictable behavior or denial of service.


Active exploitation of CVE-2026-19490 is already established. Singapore’s Cyber Security Agency warned on September 7 that exploitation attempts had been observed, while CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 9. Canada’s Cyber Center subsequently urged emergency patching and monitoring for unauthorized access.
Those facts fueled uncertainty over whether the latest alarm concerned the known authentication bypass or genuinely new zero-days; watchTowr’s later wording explicitly characterized the reported issues as two unpatched RCE flaws.
For the August vulnerabilities, Citrix advises upgrading NetScaler ADC and Gateway 14.1 to 14.1-73.32 or later and 13.1 to 13.1-63.21 or later. Fixed baselines for specialized editions are 14.1-73.32 FIPS and 13.1-37.277 for FIPS or NDcPP. Citrix lists no workaround for those flaws, and its bulletin applies to customer-managed appliances rather than Citrix-managed cloud services.
Until Citrix clarifies the new RCE reports, defenders should inventory every NetScaler instance, confirm exact builds and exposure, restrict management access, and place compensating controls before public interfaces.
Security teams should preserve logs and forensic images, review authentication events, new sessions, configuration changes, unexpected processes, suspicious files, and anomalous outbound connections, and avoid wiping potentially compromised devices before collecting evidence.
Organizations unable to accept the residual risk should isolate or shut down exposed appliances under an approved business-continuity process. Teams should also monitor Citrix’s security bulletin channel for patches and deployment guidance rather than relying on social-media fragments alone.
The episode again shows why internet-facing remote-access infrastructure demands rapid asset discovery, tested emergency patching, centralized logging, and rehearsed incident-response procedures, especially when defenders must act before complete technical disclosure arrives.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.