AI Weekly Malaysia

Back to items Summaries

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

ID
29071
Status
summarized
Published
27 Sep 2026, 3:47 PM
Fetched
28 Sep 2026, 1:59 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
28 Sep 2026, 2:01 AM
Tags
Audience
developers

What happened

Security firm watchTowr said on September 26, 2026 that two unpatched remote code execution vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited, with no CVE IDs, no indicators of compromise, and no vendor workaround published. Citrix has not confirmed the flaws, and watchTowr said Citrix communications and patches were expected early in the week of September 28; it has published no evidence, named no victim, and not said whose forensic investigations surfaced the exploitation. Some administrators on r/Citrix said they took appliances offline after being told to shut them down immediately, while Citrix has not said whether the August builds 14.1-73.32 and 13.1-63.21 or newer builds are affected. These are separate from the authentication bypass CVE-2026-19490 that Citrix fixed on August 19 and CISA added to its Known Exploited Vulnerabilities catalog on September 9.

Why it matters

If you run NetScaler ADC or Gateway at the network edge for VPN, remote access, load balancing, or authentication, you currently have no patch, no workaround, and no IOCs to hunt with — the only levers described are isolating or taking the appliance offline, or restricting its exposure, until Citrix ships fixes expected the week of September 28. If you don't run Citrix edge appliances, nothing here changes your week; the story is a reminder of how much sits behind pre-auth edge boxes, not an action item for most builders.

Discussion angle

When there is no patch, no workaround, and no IOCs, what is your actual decision process for an internet-facing appliance — and how would you even inventory whether anyone on your team or your vendors is running one?

Top