Unpatched Citrix NetScaler RCE Zero-Days Reportedly Exploited
watchTowr says two unpatched Citrix NetScaler RCE flaws are exploited, but Citrix has not confirmed or patched them.
watchTowr said on September 26 that two unpatched remote code execution flaws in Citrix NetScaler ADC and NetScaler Gateway are zero-days found during forensic work and exploited in the wild. Citrix had not confirmed the bugs or issued CVE identifiers, affected-build details, indicators, a workaround, an advisory, or a fix; watchTowr expects vendor communications early in the week of September 28. One report describes the exploitation as alleged, while the other says the flaws are under active exploitation, though both agree Citrix has not confirmed them. The reports say the issues are separate from August flaws CVE-2026-19490, a CVSS 9.3 authentication bypass patched on August 19 and added to CISA’s KEV catalog on September 9, and, according to one source, CVE-2026-19489, a CVSS 8.8 memory-overflow issue. No victims have been named. Defenders are urged to inventory exposure, restrict management access, and preserve logs, and some administrators have powered appliances off; NetScaler 13.1 reached end of maintenance on September 15, 2026.
- watchTowr said on September 26 that two unpatched remote code execution flaws in Citrix NetScaler ADC and NetScaler Gateway were found during forensic work and are reportedly exploited in the wild.
- Citrix has not confirmed the flaws and has not published CVE identifiers, affected builds, indicators of compromise, a workaround, an advisory, or a patch.
- Sources differ on certainty: one calls the exploitation alleged, while the other says the flaws are under active exploitation; both say Citrix has not confirmed them.
- The issues are distinct from CVE-2026-19490, a CVSS 9.3 authentication bypass patched on August 19 and added to CISA’s KEV catalog on September 9, and, per one report, CVE-2026-19489, a CVSS 8.8 memory-overflow issue.
- No victims have been named; watchTowr expects Citrix communications early in the week of September 28.
- Defenders are urged to inventory exposed appliances, restrict management access, preserve logs, and isolate systems if residual risk is unacceptable; some administrators have powered appliances off.
- NetScaler 13.1 reached end of maintenance on September 15, 2026.
Coverage timelineoldest first · each row is one article
- · 6h agoCitrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks
Cyber Security News· 82
watchTowr warns two unpatched Citrix NetScaler RCE zero-days are allegedly exploited, without Citrix confirmation.
- · 2h agoWarning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
The Hacker News· 88
watchTowr says two unpatched Citrix NetScaler remote code execution zero-days are under active exploitation.
Vulnerabilities in this storyAll →
- CVE-2026-194898.8<1%Unauthenticated Buffer Overflow in Citrix NetScaler ADC and NetScaler Gatewaypublished · Citrix NetScaler ADC (formerly Citrix ADC)
- CVE-2026-194909.37%Remote Authentication Bypass in Citrix NetScaler ADC and NetScaler Gateway