Close Menu
NCIJ Network NCIJ Network
    What's Hot

    ‘Russian sleeper cell’: Can Germany’s far-right AfD be barred from sensitive intel?

    September 27, 2026

    UK politics live: Burnham says NHS will ‘break’ without social care reform ahead of Labour conference | Politics

    September 27, 2026

    The Aeropod automates soil aeration without robotics — see it at TechCrunch Disrupt

    September 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • ‘Russian sleeper cell’: Can Germany’s far-right AfD be barred from sensitive intel?
    • UK politics live: Burnham says NHS will ‘break’ without social care reform ahead of Labour conference | Politics
    • The Aeropod automates soil aeration without robotics — see it at TechCrunch Disrupt
    • Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
    • Magic Eden Warns Old Ethereum NFT Listings Are Exposed to Payment Processor Exploit
    • Don’t toss cannabis leaves: They may contain rare compounds with medical potential
    • Suffolk and Essex NHS remove 10 staff over Noah Woods data breach
    • Iran waiting for official US response after Trump rejects Hormuz deal, minister says
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, September 27
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 27, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 27, 2026Vulnerability / Network Security

    Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.

    Citrix has not confirmed the flaws or published a fix. Some administrators say they have taken appliances offline rather than wait for one to be available.

    NetScaler ADC and NetScaler Gateway sit at the edge of enterprise networks, where they handle VPN and remote access, load balancing, and user authentication.

    The new flaws are not the authentication bypass, CVE-2026-19490, that Citrix fixed on August 19 and that CISA added to its Known Exploited Vulnerabilities catalog on September 9.

    watchTowr described the new flaws as unpatched, and a fix for the bypass has existed since August 19. Citrix has not said whether appliances on the August builds, 14.1-73.32 and 13.1-63.21, or any newer builds, are affected by the new flaws.

    Cybersecurity

    watchTowr’s first post on X on September 26 said it was reacting to rumors of several unpatched NetScaler RCE vulnerabilities in the wild. “While details are scarce, the information is credible,” it wrote.

    A follow-up post at 22:19 UTC gave the fuller account: two vulnerabilities, both remote code execution, both unpatched, exploited before any fix existed, discovered during forensic investigations, and Citrix communications and patches expected early in the week of September 28. It directed further questions to Citrix.

    The firm has published no evidence, named no victim, and has not said whose forensic investigations found the exploitation. In August it showed that a NetScaler heap overflow Citrix had patched in June could be used for remote code execution.

    Reports of shutdown advice appeared on Reddit the same day. An administrator posting on r/Citrix wrote that their IT supplier’s security team had phoned to advise shutting their NetScalers down immediately, without giving details. Others in the thread said their organizations had done the same.

    The source of the suppliers’ warning is not established. With no bulletin, there is no vendor workaround, and no indicators of compromise for the new flaws have been published. Until a fix ships, the decision for anyone running a NetScaler is whether to keep it online, isolate it, or power it off, and whether to treat it as already compromised.

    Because the exploitation, as watchTowr describes it, happened before any fix existed, installing the fix will not tell an operator whether an attacker got in first.

    In 2025, after a NetScaler flaw was exploited as a zero-day against Dutch organizations, the Netherlands’ National Cyber Security Center said that updating alone did not remove the risk, because an attacker could keep access gained before the patch, and told administrators to run its check scripts.

    Cybersecurity

    Citrix’s existing guidance for a suspected NetScaler compromise says to:

    • Preserve evidence first: a snapshot of a VPX instance, the logs held on remote syslog servers and NetScaler Console, a technical support bundle, and a core dump of the packet engine.
    • Isolate the appliance from the network.
    • Change every service account password and secret stored on it, reset the passwords of users who signed in through it, and revoke its certificates and private keys.
    • Keep the management interface off the internet. “The NetScaler Management Services should never be exposed to the public internet,” the guidance says.

    The Dutch agency’s 2025 check scripts, which cover a live appliance, core dumps, and full NetScaler images, are a further option, with limits.

    The README for the live-appliance script says it looks for files that indicate compromise, is not specific to one vulnerability, and comes with no guarantee of effectiveness. The code was last updated in September 2025.

    Which versions of NetScaler would receive a fix is also open. NetScaler 13.1 reached End of Maintenance on September 15 under Citrix’s release schedule, and Citrix has not said whether it will get one.

    Citrix had published nothing about the new flaws as of Sunday morning. The Hacker News has asked Cloud Software Group, the company that owns Citrix and NetScaler, and watchTowr for comment.

    active Citrix exploitation NetScaler RCE unpatched warning ZeroDays
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    OpenAI’s AI agents accidentally uploaded user-provided images to third-party sites

    GitHub Actions re-enabled with Mini Shai-Hulud payload still active

    ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

    Windows, Linux, Android File Notification Systems Leak User Activity

    China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks

    Microsoft pauses KB5002907 update after Office license deactivations

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    ‘Russian sleeper cell’: Can Germany’s far-right AfD be barred from sensitive intel?

    September 27, 2026

    UK politics live: Burnham says NHS will ‘break’ without social care reform ahead of Labour conference | Politics

    September 27, 2026

    The Aeropod automates soil aeration without robotics — see it at TechCrunch Disrupt

    September 27, 2026

    Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

    September 27, 2026
    Latest Posts

    5 Best AI Notetakers (2026), Tested and Reviewed

    August 6, 2026

    All schools to get pupil attendance targets, government says

    August 6, 2026

    Trump vows to find ‘leakers’ after reports of depleted Iran war munitions | US-Israel war on Iran News

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    ‘Russian sleeper cell’: Can Germany’s far-right AfD be barred from sensitive intel?

    September 27, 2026

    UK politics live: Burnham says NHS will ‘break’ without social care reform ahead of Labour conference | Politics

    September 27, 2026

    The Aeropod automates soil aeration without robotics — see it at TechCrunch Disrupt

    September 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.