HomeSecurityCitrix NetScaler RCE: Two new zero-day vulnerabilities in active exploitation

Citrix NetScaler RCE: Two new zero-day vulnerabilities in active exploitation

Reports of Citrix NetScaler RCE are causing renewed concern among cybersecurity teams, as two previously unknown vulnerabilities are reportedly already being exploited in real-world attacks. WatchTowr reported two zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway, with no patch yet available from Citrix.

Citrix NetScaler RCE in network infrastructure

The warning is not based on published CVE codes or technical analysis of the vulnerabilities. It comes from watchTowr, which said the two vulnerabilities allow remote code execution and were discovered during forensic investigations. The watchTowr public update highlights that the attacks occurred before a fix was available.

See also: CVE-2026-19490: The critical vulnerability in Citrix NetScaler

Citrix NetScaler RCE: What we know so far

According to The Hacker News, the vulnerabilities affect NetScaler ADC and NetScaler Gateway appliances, which sit at the edge of corporate networks and handle VPNs, remote access, load balancing, and user authentication. A successful attacker on such a device could gain a key position for further penetration.

watchTowr clarified that these are two separate, unpatched RCE vulnerabilities. No technical details, victims, indicators of compromise, or secure workaround have been published. Citrix has not publicly confirmed the reports or issued a security bulletin, with communications and fixes expected early in the week beginning September 28.

NetScaler ADC and Gateway in a corporate network

The new case should not be confused with CVE-2026-19490, the critical authentication bypass that Citrix patched on August 19 and CISA added to the KEV list on September 9. That vulnerability already has a patch available. The two new vulnerabilities described by watchTowr are considered separate incidents, with no official numbering yet.

The timing increases the pressure on administrators. Past experience with vulnerabilities in remote access devices shows that peripheral systems can become the initial point of entry, even when internal servers are properly updated. That's why the inventory should not be limited to the main premises: it needs to include virtual appliances, backup environments, and infrastructure hosted by providers.

Organizations should document which systems depend on each gateway, which accounts are connected through it, and which certificates are stored locally. This way, if an emergency directive is issued or a quarantine is decided, the transition can be done in a controlled manner, without losing critical research data.

Why the Citrix NetScaler RCE report is serious

These devices are accessible from the internet and often act as a gateway to critical services. Remote code execution on such a node can allow for credential theft, access to user sessions, certificate hijacking, and migration to internal systems. The lack of an available fix significantly increases the scope for administrators to take action.

Additionally, the exploit reportedly predated the patch. This means that a future update alone is not enough to prove that a device has not been compromised. The SecNews technical team recommends that organizations treat the report as a high-priority warning, but not present as confirmed evidence what remains unverified.

See also: Citrix NetScaler: Critical Authentication Bypass Vulnerability

Security check on a NetScaler appliance

Immediate steps for administrators

Until an official guidance is published, administrators should document every NetScaler ADC and Gateway exposed to the internet, along with its exact version and active services. The management environment should not be publicly accessible. In addition, increased monitoring of logs, remote logging systems, and unusual connections is required.

If there is evidence of a breach, it is important to preserve data, isolate the device, and change passwords, credentials, certificates, and private keys stored on it. The decision to temporarily suspend operations should be based on the business risk and the availability of secure alternative access. Teams should monitor Citrix and CISA announcements for official guidance.

See also: CISA: New Cisco, Citrix, Fortinet vulnerabilities in the KEV Catalog

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

At the same time, it is useful to check remote administration settings, access rules, and sending logs to an independent system. Collecting this data early makes it easier to compare before and after the patch is released, as well as to look for any changes that are not explained by normal maintenance tasks.

The picture is expected to become clearer when Citrix issues a technical bulletin and available fixes. Until then, organizations using NetScaler should limit exposure, preserve evidence, and only consider a breach probable when specific findings emerge. A cool, evidence-based response is preferable to unconfirmed speculation.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS