Two Unpatched Citrix NetScaler Zero-Days Under Active Exploit

Two Unpatched Citrix NetScaler Zero-Days Under Active Exploit

Security firm watchTowr reports two unpatched remote code execution flaws in Citrix NetScaler ADC and Gateway are being actively exploited with no fix or workar…

Security firm watchTowr warned on September 26 that two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are being actively exploited, allowing attackers to run malicious code remotely. Citrix has not yet confirmed the flaws or released a patch, and some administrators have already taken the drastic step of powering down their appliances to prevent compromise.

NetScaler ADC (Application Delivery Controller) and NetScaler Gateway sit at the edge of corporate networks, where they handle critical functions: secure VPN connections for remote workers, load balancing to distribute traffic across servers, and user authentication before granting access to internal systems. Because these devices face the internet, a remote code execution (RCE) flaw, an attack that lets an outsider run programs on the device without permission, can give attackers a direct path into the heart of a company's network.

The two new flaws are not the authentication bypass tracked as CVE-2026-19490, which Citrix patched on August 19 and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added to its Known Exploited Vulnerabilities catalog on September 9. watchTowr, which has a track record of analyzing NetScaler vulnerabilities, described the new zero-days as fully unpatched. In August, watchTowr demonstrated how a heap overflow Citrix had patched in June could be weaponized for remote code execution, underscoring its familiarity with the platform. On September 26, the firm first posted on X about credible rumors of several unpatched NetScaler RCE vulnerabilities, then followed up with a more detailed statement at 22:19 UTC. It said both vulnerabilities enable remote code execution and have been exploited in the wild before any fix existed, and that the exploitation was discovered during forensic investigations. watchTowr directed further questions to Citrix and did not release any evidence, name any victims, or specify whose investigations uncovered the attacks. It noted that the vendor was expected to publish a security bulletin and patches early the week of September 28.

The lack of official guidance has left NetScaler operators with a hard choice. Reports on Reddit on September 26 described IT suppliers phoning customers to advise shutting NetScalers down immediately, and some organizations confirmed they had already done so. The source of those supplier warnings remains unclear. With no vendor workaround and no published indicators of compromise (clues that an attacker has been inside), anyone running a NetScaler must decide whether to keep the appliance online, isolate it from critical networks, or power it off entirely. Because the exploitation happened before any fix, installing a future patch will not tell an operator whether an attacker already broke in. As the Dutch National Cyber Security Centre noted in 2025 after a similar NetScaler zero-day, patching alone does not remove the risk if an attacker has maintained access.

Citrix's existing guidance for a suspected NetScaler compromise outlines a rigorous response. It says to preserve evidence first: take a snapshot of a virtual appliance instance, collect logs from remote syslog servers (centralized logging systems) and the NetScaler Console, create a technical support bundle, and capture a core dump (a snapshot of the packet engine's memory). Next, isolate the appliance from the network. Then change every service account password and secret stored on the device, reset the passwords of all users who signed in through it, and revoke any certificates and private keys it held. Critically, Citrix warns that the NetScaler management interface should never be exposed to the public internet. The 2025 Dutch scripts mentioned by the NCSC can scan a live appliance, core dumps, or full NetScaler images for files that suggest compromise, but they come with no guarantee of effectiveness and were last updated in September 2025.

Another open question is which versions of NetScaler would receive a fix. The NetScaler 13.1 branch reached its End of Maintenance date on September 15, meaning Citrix no longer guarantees regular security updates for it. The company has not said whether those older releases, or the August builds 14.1-73.32 and 13.1-63.21, are affected.

For any organization managing critical edge devices, including those that protect web-facing services, a security-first IT partner can help assess exposure and implement safeguards. AEU-I provides infrastructure and security consulting to help businesses keep systems hardened against emerging threats, a sensible layer of preparedness when vendor patches are still awaited.

As of Sunday morning, Citrix had not published any statement about the new flaws. The Hacker News has asked Cloud Software Group, which owns Citrix and NetScaler, and watchTowr for comment, but until a fix ships, NetScaler operators are in the uncomfortable position of having to treat their devices as already compromised.

Si të Mbroheni

  1. If your workplace uses Citrix NetScaler for remote access, contact your IT department immediately and ask if the devices have been taken offline.
  2. Do not log in to your company VPN or remote desktop until IT confirms the connection is safe, and avoid entering sensitive passwords on any potentially compromised network.
  3. Watch your work accounts for unexpected password reset emails, login alerts from unknown locations, or any unusual activity.
  4. If you help manage IT, follow Citrix's compromise response: take a snapshot of the device, isolate it from the network, and change every password and certificate stored on it.
  5. Encourage your organization to use multi-factor authentication (MFA), an extra login step like a code sent to your phone, to reduce the damage if passwords are stolen.

Dobësitë & Zgjidhjet

Termat e Shpjeguar

  • zero-day A software vulnerability that attackers are exploiting before the vendor has released a fix.
  • remote code execution (RCE) A type of attack that lets an outsider run programs on a device without permission.
  • NetScaler ADC A Citrix appliance that handles application delivery, including load balancing and traffic management.
  • NetScaler Gateway A Citrix appliance that provides secure remote access and VPN connections for users.
  • VPN (Virtual Private Network) A service that encrypts internet traffic so remote workers can safely connect to their company network.
  • core dump A snapshot of a computer's memory taken at a moment, used for diagnosing crashes or security breaches.
  • indicators of compromise (IOCs) Clues like odd files or network behavior that suggest an attacker may have broken into a system.

Shërbime AEU të lidhura

  • AEU-I Konsulencë IT dhe sigurie