Full Report
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26. Citrix has not confirmed the flaws or published a fix. Some administrators say they have taken appliances offline rather than wait for one to be available. NetScaler ADC and
Analysis Summary
# Vulnerability: Unpatched Remote Code Execution (RCE) in Citrix NetScaler
## CVE Details
* **CVE ID:** Pending (Citrix has not yet assigned identifiers for these two zero-days).
* **CVSS Score:** N/A (Estimated Critical based on RCE capability).
* **CWE:** Likely related to Memory Corruption or Improper Input Validation (Technical specifics pending vendor confirmation).
## Affected Systems
* **Products:** Citrix NetScaler ADC and NetScaler Gateway.
* **Versions:** Specific vulnerable versions are currently unconfirmed. However, vulnerabilities have been reported during the use of August 2026 builds (14.1-73.32 and 13.1-63.21).
* **Configurations:** Edge-facing appliances handling VPN, remote access, load balancing, and user authentication.
## Vulnerability Description
Security firm watchTowr has identified two distinct zero-day vulnerabilities that allow for Remote Code Execution (RCE). While full technical documentation is currently withheld to prevent further exploitation, the flaws were discovered during forensic investigations of compromised environments. These vulnerabilities are distinct from the recently patched CVE-2026-19490 (authentication bypass).
## Exploitation
* **Status:** **Exploited in the wild.** Active exploitation was detected prior to any available patch.
* **Complexity:** Medium (Rumored to require specific forensic knowledge of the appliance).
* **Attack Vector:** Network (Remote).
## Impact
* **Confidentiality:** High (Total access to data flowing through the gateway).
* **Integrity:** High (Potential for full system takeover and lateral movement).
* **Availability:** High (Administrators are proactively taking units offline to prevent breach).
## Remediation
### Patches
* **No patches currently available.** Citrix is expected to release communications and fixes during the week of September 28, 2026.
### Workarounds
* **Isolation:** Move NetScaler Management Services off the public internet immediately.
* **Decommissioning:** Some organizations are choosing to take appliances offline until a security update is verified.
* **Credential Hygiene:** Prepare to rotate all service account passwords and certificates stored on the appliance once patched.
## Detection
* **Indicators of Compromise:** No specific IoCs for these two flaws have been released yet.
* **Detection Methods:**
* Monitor for unusual outbound traffic from NetScaler appliances.
* Review remote syslog servers and NetScaler Console logs for unauthorized access.
* Use the Netherlands' National Cyber Security Center (NCSC-NL) check scripts (available on GitHub) to scan for general indicators of NetScaler compromise.
## References
* [Citrix Support - Suspected Compromise Steps] hxxps[://]support[.]citrix[.]com/external/article/CTX694799/
* [watchTowr Labs] hxxps[://]labs[.]watchtowr[.]com/
* [NCSC-NL Citrix Detection Scripts] hxxps[://]github[.]com/NCSC-NL/citrix-2025/