Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Citrix admins warned to shut down NetScalers over 2 exploited zero-days

    September 27, 2026

    ETH news: Ethereum may not be ‘just a blockchain’ in 2030, Vitalik Buterin says

    September 27, 2026

    Gunmen kill at least 27 people in separate mass shootings in South Africa

    September 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Citrix admins warned to shut down NetScalers over 2 exploited zero-days
    • ETH news: Ethereum may not be ‘just a blockchain’ in 2030, Vitalik Buterin says
    • Gunmen kill at least 27 people in separate mass shootings in South Africa
    • Social care reform could mean big risks and big rewards for Burnham
    • You Don’t Need to Pay for Distraction-Blocking Software
    • Cloudflare fixes Containers cross-tenant flaw exposing customer data
    • Bitcoin’s Quantum Problem: Three Ways Researchers Are Trying to Fix It
    • Glucosamine, a popular joint supplement, linked to faster Alzheimer’s progression
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, September 27
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Citrix admins warned to shut down NetScalers over 2 exploited zero-days

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 27, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week.

    The first signs of the incident appeared when Citrix administrators began reporting on Reddit that IT suppliers and security teams were privately contacting their organizations and advising them to shut down their NetScaler appliances.

    “We got a call from our IT supplier’s security team, they couldn’t give any details but they advised to shut our Netscalers down immediately,” one administrator wrote.

    Other administrators said law enforcement, CERTs, and national cybersecurity agencies had also been contacting organizations about the issue.

    Cybersecurity firm watchTowr later publicly warned that it was “rapidly reacting to rumors” that multiple unpatched Citrix NetScaler remote code execution vulnerabilities were being exploited in the wild after verifying the information with “authoratitive sources.”

    “We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the information is credible,” watchTowr said.

    watchTowr said the warning is not related to CVE-2026-19490 and CVE-2026-19489, two NetScaler flaws disclosed by Citrix in August.

    CVE-2026-19490 is a critical authentication bypass vulnerability affecting NetScaler appliances configured as an AAA virtual server or Gateway under certain configurations.

    As BleepingComputer reported earlier this month, researchers began observing attempts to exploit CVE-2026-19490 after a proof-of-concept exploit became public.

    CISA later added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog on September 9.

    watchTowr later shared more information, saying the current incident involves two remote code execution vulnerabilities that remain unpatched and have already been exploited in the wild.

    “Citrix comms & patches are expected early next week,” watchTowr said.

    “Two vulnerabilities – both RCE. Unpatched, 0days. Exploited in-the-wild – discovered during forensics.”

    BleepingComputer contacted Citrix about the reported zero-days but received no response.

    NCSC warning provides additional details

    The Dutch National Cyber Security Center (NCSC-NL) later shared additional details in a reported pre-notification advisory sent to organizations in the Netherlands.

    Multiple people shared copies of the notification online, which says the agency received information from a European partner CERT regarding two critical zero-day vulnerabilities in Citrix NetScaler.

    According to the notification, each vulnerability can independently lead to remote code execution, with one allowing attackers to place shellcode directly into memory. Technical details about the second vulnerability were still being researched.

    The notice says no CVE identifiers had been assigned and that Citrix had not published an advisory, but was working on patches expected to be released early next week.

    It also states that no indicators of compromise were available at the time and that the NCSC was in contact with Citrix to obtain additional technical information and possible IoCs.

    According to the notification, Citrix discovered the vulnerabilities during an incident response investigation in customer environments.

    Those investigations identified active exploitation, after which Citrix submitted a notification under the European Union’s Cyber Resilience Act.

    The NCSC notification says exploitation has been identified in multiple Citrix customers worldwide, although the agency did not know whether the vulnerabilities were being exploited on a widespread scale.

    It also warned that exploitation attempts could increase after Citrix publishes patches and additional technical details about the vulnerabilities.

    Because updating NetScaler appliances can cause downtime, the NCSC said the pre-notification was meant to give organizations time to prepare and implement safeguards where possible, and to install patches quickly once Citrix releases them.

    BleepingComputer contacted the Dutch NCSC to confirm whether the advisory circulating online was legitimate.

    The agency declined to confirm the notification, but its response mirrors reports from Citrix administrators who said cybersecurity agencies had privately shared information about the vulnerabilities.

    “As part of our role as the National CSIRT and sectoral CSIRT for designated organizations, the NCSC-NL monitors relevant developments and cyber threats affecting the Netherlands 24/7,” the NCSC-NL told BleepingComputer.

    “We provide information and advice to organizations so that they can take appropriate measures. As you’re not part of our constituency, we cannot disclose any further information at this time.”

    Citrix has not officially disclosed the two vulnerabilities, and no publicly available CVE identifiers, affected version information, indicators of compromise, or official mitigation guidance exist for the reported zero-days.

    Until Citrix releases patches or official guidance, administrators should take Internet-exposed NetScaler appliances offline where possible, or restrict access to trusted networks and IP addresses to reduce their risk.

    At a minimum, do not expose NetScaler management interfaces to the Internet, and restrict access to trusted IP addresses.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    admins Citrix Exploited NetScalers Shut warned ZeroDays
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Cloudflare fixes Containers cross-tenant flaw exposing customer data

    Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

    Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

    OpenAI’s AI agents accidentally uploaded user-provided images to third-party sites

    GitHub Actions re-enabled with Mini Shai-Hulud payload still active

    ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Citrix admins warned to shut down NetScalers over 2 exploited zero-days

    September 27, 2026

    ETH news: Ethereum may not be ‘just a blockchain’ in 2030, Vitalik Buterin says

    September 27, 2026

    Gunmen kill at least 27 people in separate mass shootings in South Africa

    September 27, 2026

    Social care reform could mean big risks and big rewards for Burnham

    September 27, 2026
    Latest Posts

    Inside the Secretive Deal for a $10 Billion Data Center in Rural North Carolina

    August 6, 2026

    Sugar may have been a key ingredient in human evolution

    August 6, 2026

    Hyperscale sells Bitcoin for AI business set to deliver less than 20% of 2027 revenue

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Citrix admins warned to shut down NetScalers over 2 exploited zero-days

    September 27, 2026

    ETH news: Ethereum may not be ‘just a blockchain’ in 2030, Vitalik Buterin says

    September 27, 2026

    Gunmen kill at least 27 people in separate mass shootings in South Africa

    September 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.