Citrix Admins Urged to Shut Down NetScaler Appliances as Two Zero-Day RCE Flaws Exploited in the Wild

Cybersecurity agencies and researchers privately warn of critical vulnerabilities; patches expected next week

By LineZotpaper
Published
Read Time2 min
Two unpatched remote code execution zero-day vulnerabilities in Citrix NetScaler are reportedly being actively exploited, prompting cybersecurity agencies, security researchers, and IT providers to privately warn organizations to shut down their appliances. Patches are expected early next week, according to researchers tracking the incident.

Organizations using Citrix NetScaler appliances are being urgently warned to shut down their devices following reports of two unpatched remote code execution (RCE) vulnerabilities being exploited in the wild.

Administrators on Reddit reported receiving calls from IT suppliers and security teams advising immediate shutdowns. One administrator wrote: "We got a call from our IT supplier's security team, they couldn't give any details but they advised to shut our Netscalers down immediately." Others said law enforcement, CERTs and national cybersecurity agencies had also been contacting organisations about the issue.

Cybersecurity firm watchTowr publicly warned that it was "rapidly reacting to rumors" that multiple unpatched Citrix NetScaler RCE vulnerabilities were being exploited, verifying the information with authoritative sources. watchTowr later confirmed two vulnerabilities, both RCE, unpatched zero-days exploited in the wild, discovered during forensics.

The Dutch National Cyber Security Center (NCSC-NL) shared a pre-notification advisory stating each vulnerability can independently lead to remote code execution, with one allowing attackers to place shellcode directly into memory.

The current incident is not related to CVE-2026-19490 and CVE-2026-19489, two NetScaler flaws disclosed by Citrix in August, one of which (CVE-2026-19490) was a critical authentication bypass already added to CISA's Known Exploited Vulnerabilities catalog on September 9 after a proof-of-concept exploit became public.

BleepingComputer contacted Citrix for comment but received no response.

§

Analysis

Why This Matters

  • Organizations using Citrix NetScaler face urgent security risks; active exploitation means attackers may already have compromised systems
  • The vulnerabilities allow remote code execution without authentication, potentially granting full control over affected appliances
  • Until patches arrive next week, the only mitigation advised is shutting down NetScaler appliances, which can disrupt remote access for large enterprises

Background

Citrix NetScaler appliances are widely used for application delivery and remote access. The current incident involves two new zero-day vulnerabilities that are separate from previously disclosed flaws. watchTowr researchers discovered the vulnerabilities during forensic analysis, indicating attackers may have been exploiting them for some time. Patches are reportedly scheduled for early next week from Citrix.

Key Perspectives

Organizations and IT administrators: They face a difficult choice between maintaining critical remote access services and the risk of compromise. Many have received direct warnings from security partners and government agencies. Citrix: The company has not publicly commented on the reported zero-days. Patches are expected early next week, suggesting awareness and active work on fixes. Security researchers (watchTowr, NCSC-NL): They have issued private and limited public warnings to give organizations time to prepare defensive measures before full details and exploits become widely available.

What to Watch

  • Citrix's patch release early next week, and whether it covers both vulnerabilities
  • CISA potentially adding these zero-days to its Known Exploited Vulnerabilities catalog
  • Disclosure of technical details or proof-of-concept exploits after patches are released, which could lead to broader attacks on unpatched systems

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.