Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
- ID
- 29071
- Status
- summarized
- Published
- 27 Sep 2026, 3:47 PM
- Fetched
- 28 Sep 2026, 1:59 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 28 Sep 2026, 2:01 AM
- Tags
- Audience
- developers
What happened
Security firm watchTowr said on September 26, 2026 that two unpatched remote code execution vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited, with no CVE IDs, no indicators of compromise, and no vendor workaround published. Citrix has not confirmed the flaws, and watchTowr said Citrix communications and patches were expected early in the week of September 28; it has published no evidence, named no victim, and not said whose forensic investigations surfaced the exploitation. Some administrators on r/Citrix said they took appliances offline after being told to shut them down immediately, while Citrix has not said whether the August builds 14.1-73.32 and 13.1-63.21 or newer builds are affected. These are separate from the authentication bypass CVE-2026-19490 that Citrix fixed on August 19 and CISA added to its Known Exploited Vulnerabilities catalog on September 9.
Why it matters
If you run NetScaler ADC or Gateway at the network edge for VPN, remote access, load balancing, or authentication, you currently have no patch, no workaround, and no IOCs to hunt with — the only levers described are isolating or taking the appliance offline, or restricting its exposure, until Citrix ships fixes expected the week of September 28. If you don't run Citrix edge appliances, nothing here changes your week; the story is a reminder of how much sits behind pre-auth edge boxes, not an action item for most builders.
Discussion angle
When there is no patch, no workaround, and no IOCs, what is your actual decision process for an internet-facing appliance — and how would you even inventory whether anyone on your team or your vendors is running one?