Threat Intelligence

Two Unpatched Citrix NetScaler Flaws Being Exploited Right Now, No Fix Yet

The Hacker News · 27 Sept 2026
Key Takeaway If your business runs Citrix NetScaler ADC or Gateway appliances, consider isolating or taking them offline until Citrix issues an official patch, and monitor for updates closely.

Security firm watchTowr revealed on September 26 that it has credible information about two new zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances. Both flaws allow remote code execution and were reportedly exploited in the wild before any fix existed. These are separate from an earlier authentication bypass flaw, CVE-2026-19490, which Citrix patched in August and CISA added to its Known Exploited Vulnerabilities list in September.

Citrix has not yet confirmed the new vulnerabilities or released a patch, though watchTowr says communications and a fix are expected in the coming week. NetScaler devices sit at the edge of corporate networks, managing VPN access, load balancing, and authentication, making them a high-value target for attackers. Reports have surfaced on Reddit of IT security suppliers advising businesses to shut down their NetScaler appliances immediately as a precaution, though the origin of this advice and technical details of the exploits remain unconfirmed.

With no vendor bulletin, workaround, or published indicators of compromise, organisations running NetScaler appliances face a difficult choice: keep systems online, isolate them from the network, or power them down entirely until more information or a patch becomes available.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.