Organizations using Citrix NetScaler appliances are being urgently warned to shut down their devices following reports of two unpatched remote code execution (RCE) vulnerabilities being exploited in the wild.
Administrators on Reddit reported receiving calls from IT suppliers and security teams advising immediate shutdowns. One administrator wrote: "We got a call from our IT supplier's security team, they couldn't give any details but they advised to shut our Netscalers down immediately." Others said law enforcement, CERTs and national cybersecurity agencies had also been contacting organisations about the issue.
Cybersecurity firm watchTowr publicly warned that it was "rapidly reacting to rumors" that multiple unpatched Citrix NetScaler RCE vulnerabilities were being exploited, verifying the information with authoritative sources. watchTowr later confirmed two vulnerabilities, both RCE, unpatched zero-days exploited in the wild, discovered during forensics.
The Dutch National Cyber Security Center (NCSC-NL) shared a pre-notification advisory stating each vulnerability can independently lead to remote code execution, with one allowing attackers to place shellcode directly into memory.
The current incident is not related to CVE-2026-19490 and CVE-2026-19489, two NetScaler flaws disclosed by Citrix in August, one of which (CVE-2026-19490) was a critical authentication bypass already added to CISA's Known Exploited Vulnerabilities catalog on September 9 after a proof-of-concept exploit became public.
BleepingComputer contacted Citrix for comment but received no response.