Citrix NetScaler: watchTowr warns of two unpatched RCE zero-days under active exploitation (no Citrix bulletin yet)
watchTowr (Infosec Exchange, 26 September 2026 16:57 UTC, follow-up 22:19 UTC) says it is reacting to credible reports of multiple unpatched Citrix NetScaler ADC / NetScaler Gateway remote code execution vulnerabilities circulating in the wild, and later stated there are two RCE flaws, both unpatched zero-days, exploited before any fix existed and discovered during forensic investigations, with Citrix communications and patches expected early in the week of 28 September 2026. The Hacker News (27 Sep) amplifies the same account and notes these are distinct from CVE-2026-19490 (auth bypass patched 19 Aug / CISA KEV 9 Sep). Citrix has not published a security bulletin, CVE IDs, workarounds, or IoCs for the new flaws as of this desk pass; some administrators report taking appliances offline. Until a vendor fix ships, operators must decide whether to keep NetScaler online, isolate it, or power it off, and treat pre-patch compromise as possible. Preserve evidence before rebuilds; follow existing Citrix compromise guidance (snapshot/logs/support bundle, isolate, rotate secrets/certs, keep management off the internet). Primary: watchTowr; wire: The Hacker News.
- Product
- Citrix NetScaler ADC and NetScaler Gateway (customer-managed edge appliances)
- Versions
- Unconfirmed — Citrix has not stated whether August fixed builds (e.g. 14.1-73.32 / 13.1-63.21 for CVE-2026-19490) or newer builds are affected by these new flaws
- Exploited in Australia?
- unknown
- Patch to
- No vendor patch/CVE/IoCs published yet — monitor Citrix Security Bulletins for expected early-week-of-28-Sep comms; until then consider isolating or powering off internet-facing NetScaler; preserve VPX snapshot / remote syslog / support bundle / packet-engine core before rebuild; rotate service-account passwords, user passwords that authenticated through the appliance, and revoke certificates/keys; keep NetScaler management services off the public internet; do not assume prior CVE-2026-19490/19489 patches cover these new flaws
Primary: watchTowr — two unpatched NetScaler RCE 0-days, exploited in forensics; patches expected early week of 28 Sep (26 Sep 2026 22:19 UTC) · Vendor: Citrix Security Bulletins (no new NetScaler bulletin for these flaws as of 27 Sep 2026 desk pass) · CVE: CVE-2026-19490 · The Hacker News — Two unpatched Citrix NetScaler RCE zero-days under active exploitation (27 Sep 2026)
