Citrix NetScaler zero-day RCE flaws actively exploited

Two previously unknown remote code execution zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are being actively exploited, prompting some organizations to pull critical devices offline amid a lack of confirmed fixes or advisories from the vendor[1][3][8].

Researchers at security firm watchTowr reported that attackers are abusing two distinct flaws to achieve remote code execution on exposed NetScaler appliances, saying the issues were discovered during incident response work and are already being used in real-world intrusions[1][3][14]. The bugs appear to affect internet-facing ADC and Gateway deployments used for application delivery and remote access, significantly amplifying the potential blast radius when compromised[1][3].

At the time of writing, Citrix had not publicly confirmed the vulnerabilities, assigned CVE identifiers, or released technical guidance, leaving defenders to make difficult risk decisions based on limited information[1][3][6][8]. Several administrators quoted in early coverage say they have opted to take NetScaler appliances offline, restrict external access, or shift traffic onto alternative platforms rather than continue running potentially exposed systems without a vendor-backed mitigation or patch timeline[1][6][8].

The discovery of the new zero-days comes on the heels of a critical authentication bypass in NetScaler ADC and Gateway, tracked as CVE-2026-19490, which Citrix disclosed and patched in August and which carries a high CVSSv3 score of 9.3 for its ability to allow unauthenticated access to gateway and AAA virtual server configurations[5][7][11]. National cyber agencies subsequently urged organizations to upgrade to fixed builds such as 14.1-73.32 and 13.1-63.21 and added CVE-2026-19490 to exploit-tracking catalogs, underscoring ongoing attacker interest in NetScaler as a beachhead into enterprise networks[7][12][15].

Current reporting suggests the newly observed zero-days are separate from CVE-2026-19490 and remain unpatched, with watchTowr and other outlets expecting Citrix to release communications and fixes in the coming days but offering few technical details until that happens[1][3][14]. In the meantime, security teams are advised to inventory all NetScaler ADC and Gateway instances, reduce or eliminate direct internet exposure where possible, apply all existing Citrix patches including those for CVE-2026-19490, and scrutinize logs for suspicious authentication patterns or command execution that could indicate exploitation attempts[5][7][12][15].

Until Citrix publishes an official advisory and remediation guidance, organizations running NetScaler in high-value roles such as VPN gateways or SAML identity providers should treat these zero-days as an active threat and prepare response playbooks for the possibility of compromise[1][3][7]. Given the platform’s history of high-severity bugs and documented zero-day exploitation, prioritizing isolation, rigorous monitoring, and rapid patching of known issues is likely to be the most effective way to blunt the impact of the current wave of attacks while the security community waits for more concrete technical information[10][11][13].

References

  1. Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
  2. Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks
  3. NVD-CVE-2026-19490 – NIST
  4. Citrix NetScaler: Zwei RCE-Zero-Days werden aktiv ausgenutzt – noch kein Fix
  5. AL26-019 – Vulnerabilities impacting Citrix NetScaler ADC and …
  6. Citrix NetScaler: Zwei unpatched RCE-Zero-Days werden aktiv ausgenutzt
  7. Citrix fixes critical NetScaler RCE flaw exploited in zero-day attacks
  8. CISA Gives Federal Agencies Until Today to Patch a …
  9. Critical vulnerabilities in Citrix NetScaler Application … – Cyber.gov.au
  10. Latest Netscaler news
  11. Cyber Security News
  12. CVE-2026-19490 vào KEV: NetScaler phải nâng bản

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply