Skip to main content
Emerging Threats

Citrix NetScaler Zero-Days Exploited in Wild Ahead of Patches

Concerned system administrators sit at consoles near computer servers and networking equipment, with a prominent…

"We got a call from our IT supplier's security team, they couldn't give any details but they advised to shut our Netscalers down immediately," wrote one Citrix administrator on Reddit, capturing the abrupt, private warnings that began circulating among NetScaler operators.

Reddit reports and early private warnings

Citrix administrators first signaled trouble when IT suppliers, security teams, law enforcement, CERTs and national cybersecurity agencies began contacting organizations privately and advising immediate action. Multiple administrators posted on Reddit that they had been urged to shut down NetScaler appliances without public detail on the underlying cause. BleepingComputer reached out to Citrix and received no response.

watchTowr's public alert: two unpatched RCE zero-days

Security firm watchTowr moved from private correspondence to public warning, saying it was "rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild." The company said the report was "credible" after verification with "authoratitive sources" and emphasized the incident was not related to two NetScaler flaws disclosed by Citrix in August—CVE-2026-19490 and CVE-2026-19489.

watchTowr later stated more explicitly that the incident involves "two vulnerabilities - both RCE. Unpatched, 0days. Exploited in-the-wild - discovered during forensics." The firm said Citrix communications and patches were "expected early next week."

Dutch NCSC pre-notification: two critical zero-days and one shellcode-capable flaw

The Dutch National Cyber Security Center (NCSC-NL) circulated a pre-notification advisory, obtained and shared online by multiple people, after receiving information from a European partner CERT. According to that notice, each of the two vulnerabilities can independently lead to remote code execution; one specifically allows attackers to place shellcode directly into memory while details of the second remained under research.

The NCSC-NL notice said no CVE identifiers had been assigned and that Citrix had not yet published an advisory, but that patches were expected "early next week." The pre-notification warned that no indicators of compromise (IoCs) were available at the time and that the NCSC was in contact with Citrix to obtain additional technical information and possible IoCs.

Citrix discovery, EU Cyber Resilience Act notification, and scope of exploitation

According to the NCSC notification, Citrix discovered the vulnerabilities during incident response investigations in customer environments; those investigations identified active exploitation. Citrix subsequently submitted a notification under the European Union's Cyber Resilience Act. The NCSC said exploitation had been identified in multiple Citrix customers worldwide but did not characterize whether exploitation was widespread.

The advisory also cautioned that exploitation attempts could increase after Citrix publishes patches and additional technical details—an explicit acknowledgment that disclosures can drive scanning and exploitation if mitigations are not yet widely applied.

What this means for IT administrators, national CERTs, and Citrix customers

  • IT administrators and security teams: Immediate action was the consistent private message—take Internet-exposed NetScaler appliances offline where possible or restrict access to trusted networks and IP addresses. The NCSC stressed that updates can cause downtime, and recommended preparing for patch-related service interruptions.
  • National CERTs and regulators: The incident illustrates active information-sharing between CERTs and affected vendors: the NCSC received details from a partner CERT and is coordinating with Citrix. The vendor's EU Cyber Resilience Act notification demonstrates regulator-facing reporting in progress.
  • Citrix customers and procurement leaders: Organizations should expect patches and an official advisory from Citrix "early next week" and should prioritize testing and scheduling updates rapidly while accounting for potential downtime. The NCSC and watchTowr both noted the absence of public IoCs, CVE assignments, affected-version lists, or official mitigation guidance until Citrix publishes them.

Short-term mitigations and final observations

With no official Citrix advisory yet, security providers and the NCSC offered concrete tactical steps: do not expose NetScaler management interfaces to the Internet, restrict access to trusted IP addresses, or take Internet-facing appliances offline where feasible. These measures aim to reduce immediate attack surface until vendor-supplied patches and technical indicators are available.

Two realities frame the coming days. First, Citrix customers already discovered to be affected were at the center of the vendor's incident-response work and regulatory notification—meaning known exploitation has occurred inside real environments. Second, both watchTowr and the NCSC warned that further exploitation could rise once Citrix issues patches and technical details, underscoring the narrow window for organizations to prepare before public disclosure expands the information available to both defenders and attackers.

For administrators, the choice is operational and immediate: accept planned downtime to remove public exposure now, or wait for vendor fixes and risk additional, possibly automated, attempts at remote code execution. For CERTs and vendors, the situation will test coordination as patches, advisories, and IoCs must flow quickly to contain an active, unpatched threat.

Original reporting: BleepingComputer — Citrix admins warned to shut down NetScalers over 2 exploited zero-days