"While details are scarce, the information is credible," watchTowr wrote on X on September 26, as it raised the alarm about two new remote-code-execution zero-days affecting Citrix NetScaler appliances that, the firm says, are already being exploited in the wild.
watchTowr's disclosure and timeline
On September 26 security firm watchTowr posted first on X that it was reacting to "rumors of several unpatched NetScaler RCE vulnerabilities in the wild." A follow-up post at 22:19 UTC expanded the claim: the firm said there are two vulnerabilities, both remote code execution, both unpatched, and both "exploited before any fix existed," and that they were "discovered during forensic investigations." watchTowr said it expected Citrix communications and patches early in the week of September 28, and directed further questions to Citrix.
watchTowr has published no evidence, named no victim, and has not said whose forensic investigations found the exploitation.
What the vulnerabilities target: NetScaler ADC and NetScaler Gateway
The appliances in question — NetScaler ADC and NetScaler Gateway — sit at the edge of enterprise networks and are used to handle VPN and remote access, load balancing, and user authentication. watchTowr described the two flaws as unpatched; Citrix has not confirmed the flaws or published a fix.
watchTowr noted that these new flaws are not the authentication-bypass issue identified as CVE-2026-19490, which Citrix fixed on August 19 and which CISA added to its Known Exploited Vulnerabilities catalog on September 9. The firm also said a fix for that bypass has existed since August 19, but that Citrix has not said whether appliances running the August builds — 14.1-73.32 and 13.1-63.21 — or any newer builds are affected by the newly reported flaws.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadAdministrator reactions: shutdown advice and operational choices
On the day of watchTowr's posts, reports of shutdown advice appeared on Reddit. An administrator posting on r/Citrix wrote that their IT supplier's security team had phoned to advise shutting their NetScalers down immediately, "without giving details." Other posters in the thread said their organizations had taken the same step.
With no vendor bulletin, no published workaround, and no indicators of compromise, operators face stark choices: keep a NetScaler online, isolate it, or power it off — and whether to treat a device as already compromised. As watchTowr framed it, because exploitation occurred before any fix existed, installing a future fix will not reveal whether an attacker had already gained access.
Published guidance: Citrix steps and the Netherlands' 2025 scripts
Citrix's existing guidance for a suspected NetScaler compromise — published previously and cited by the reporting — advises administrators to preserve evidence first, isolate the appliance from the network, and rotate credentials and certificates. The guidance lists specific steps:
- Preserve evidence: a snapshot of a VPX instance, the logs held on remote syslog servers and NetScaler Console, a technical support bundle, and a core dump of the packet engine.
- Isolate the appliance from the network.
- Change every service account password and secret stored on it, reset the passwords of users who signed in through it, and revoke its certificates and private keys.
- Keep the management interface off the internet. "The NetScaler Management Services should never be exposed to the public internet," the guidance says.
As context, the Netherlands' National Cyber Security Center — responding to a 2025 zero-day exploit of a NetScaler flaw against Dutch organizations — said updating alone did not remove risk because attackers might retain access obtained before a patch, and advised administrators to run its check scripts. Those check scripts, which cover live appliances, core dumps, and full NetScaler images, are an additional option; their README says they look for files that indicate compromise, are not specific to one vulnerability, and "come with no guarantee of effectiveness." The code was last updated in September 2025.
What this means for technologists and security teams, affected enterprises and procurement leaders, and policymakers and regulators
Technologists and security teams: faced with no Citrix bulletin or indicators of compromise, teams must choose operational mitigations — isolation or shutdown — while preserving evidence such as VPX snapshots and core dumps in case of forensic follow-up. The lack of published IoCs means detection will rely on the organization's own logs and the guidance Citrix has previously published.
Affected enterprises and procurement leaders: organizations running NetScaler 13.1 should note that, under Citrix's release schedule, that line reached End of Maintenance on September 15; Citrix has not said whether 13.1 will receive a fix for these new issues. That maintenance status bears directly on whether older appliances can expect vendor updates.
Policymakers and regulators: a previously cataloged vulnerability, CVE-2026-19490, received a fix and was added to CISA's Known Exploited Vulnerabilities list; these new flaws, by contrast, are described as unpatched and reportedly exploited before a patch existed, complicating remediation and attribution work for incident responders and oversight bodies.
As of Sunday morning, Citrix had published nothing about the new flaws. The Hacker News has asked Cloud Software Group — the company that owns Citrix and NetScaler — and watchTowr for comment. Patches were expected in the week beginning September 28; until then, operators of NetScaler ADC and Gateway appliances will have to balance availability against the risk that exploitation may already have occurred.




