As reported by The Hacker News, security firm watchTowr disclosed on September 26 that two unpatched remote code execution zero-days in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited in the wild. Citrix has neither confirmed the flaws nor issued a patch. For defenders, this is among the most difficult scenarios in incident response: a critical edge device is vulnerable, no fix exists, no indicators of compromise have been published, and the appliance may already be compromised.

Security Impact: As reported by The Hacker News, security firm watchTowr disclosed on September 26 that two unpatched remote code execution zero-days in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited in the wild.

Vulnerability Summary

FieldDetails
Products AffectedCitrix NetScaler ADC, Citrix NetScaler Gateway
Vulnerability TypeRemote Code Execution (RCE) — two distinct flaws
CVE IDsNot yet assigned
SeverityCritical (RCE on edge appliances, active exploitation)
Patch AvailableNo — Citrix has not confirmed or addressed the flaws
Active ExploitationYes — discovered during forensic investigations
WorkaroundNone published by vendor
Related CVECVE-2026-19490 (auth bypass, patched August 19, 2026 — distinct from these flaws)
Expected Patch TimelineWeek of September 28, 2026 (per watchTowr)

Why This Matters More Than a Typical Zero-Day

NetScaler appliances are not just another server on the network — they are the front door. They terminate VPN sessions, load-balance critical applications, and authenticate users before they reach internal resources. An RCE on a NetScaler Gateway gives an attacker a position that is simultaneously internet-facing and trusted internally. This is the same class of device that was leveraged in the 2023 Citrix Bleed campaign (CVE-2023-4966) and the 2025 Dutch organization attacks. The pattern is now well-established: NetScaler zero-days are high-value targets for both cybercrime and state-sponsored actors.

The absence of a patch, a workaround, or IOCs creates an asymmetry that favors attackers. Defenders cannot detect what they cannot characterize, and they cannot remediate what they cannot patch.

The Post-Patch Persistence Problem

Even when Citrix releases a fix — reportedly expected early in the week of September 28 — applying it will not answer the critical question: was the appliance already compromised? The Netherlands' National Cyber Security Center made this exact point in 2025: updating alone does not remove the risk because attackers can maintain persistence established before the patch was available. Organizations that simply patch and move on may be operating on a compromised device without knowing it.

Who Is Most at Risk

Who Is Most at Risk
Organizations with internet-facing NetScaler Gateway VPNs — the highest-exposure configuration, as the RCE surface is directly reachable from the internet
Healthcare, finance, and government sectors — historically prioritized targets for NetScaler exploitation campaigns
Organizations still running pre-August 2026 builds — these are also exposed to CVE-2026-19490, compounding risk
Environments lacking network segmentation behind the NetScaler — if the appliance is compromised, lateral movement is trivial
Small and midsize enterprises — often lack 24/7 SOC coverage and may not learn of compromise until well after the fact

Shield53 Recommendations: Immediate Actions

1. Make a Go/No-Go Decision on the Appliance

If your NetScaler is internet-facing and supports remote VPN access, seriously consider taking it offline or placing it behind a WAF until a patch is available. Several administrators on public forums report their suppliers have already recommended immediate shutdown. If taking it offline is operationally impossible, restrict management interfaces to internal IPs only and reduce the attack surface by disabling any non-essential features.

2. Assume Compromise Until Proven Otherwise

Because no IOCs exist and exploitation predates any fix, treat any NetScaler that has been internet-facing in the past 30–60 days as potentially compromised. Begin forensic review now:

  • Export and preserve logs, configuration files, and memory dumps before patching — patching may destroy evidence
  • Review authentication logs for anomalous VPN sessions, especially from unexpected geographies or outside business hours
  • Check for new local accounts, modified startup scripts, or unexpected cron/scheduled tasks on the appliance
  • Examine traffic flows from the NetScaler to internal systems for signs of lateral movement or data exfiltration

3. Implement Compensating Controls

  • Place the NetScaler behind a reverse proxy or WAF that can filter anomalous requests
  • Enforce network segmentation so that a compromised NetScaler cannot reach sensitive internal subnets directly
  • Require MFA for all VPN sessions and monitor for MFA fatigue or bypass attempts
  • Deploy EDR or network detection tools on systems immediately behind the NetScaler to catch post-exploitation activity

4. Prepare for the Patch — But Plan for Validation

When Citrix releases the fix, patch immediately — but treat it as the beginning, not the end, of your response. After patching:

  • Conduct a full threat hunt across the environment for persistence mechanisms
  • Rotate all credentials that passed through the NetScaler, including service accounts and VPN user credentials
  • Review SSL/TLS certificates on the appliance for unauthorized replacement
  • Consider a clean rebuild of the appliance from a known-good image rather than an in-place upgrade, if compromise is suspected

5. Monitor for the Advisory

Watch the Citrix security bulletins page and CISA channels for the official advisory. Expect CISA to add these CVEs to the Known Exploited Vulnerabilities catalog rapidly once confirmed, which will trigger federal BOD compliance timelines and likely influence cyber insurance requirements.

Broader Implication

This event reinforces a structural problem in enterprise security: the concentration of critical functions — VPN termination, authentication, load balancing — on single-vendor edge appliances creates a single point of failure that is simultaneously a single point of exploitation. Organizations should evaluate whether their architecture can tolerate the temporary loss of such a device, and whether alternative remote access paths or redundancy exist. The organizations that weather these zero-day events best are not those with the fastest patching — they are those whose architecture assumes the edge device will eventually be compromised.