New unpatched Citrix NetScaler zero-days actively exploited, admins told to shut down devices
Citrix administrators report being privately contacted by IT suppliers, law enforcement, and cybersecurity agencies warning of two unpatched NetScaler remote code execution vulnerabilities being exploited in the wild. Security firm watchTowr confirmed the flaws are distinct from CVE-2026-19490 and CVE-2026-19489 disclosed in August, and said patches are expected next week.
GoKawiil's interpretation of the reporting above, not reported fact.
The informal, back-channel warnings rather than a public advisory suggest responders may be trying to limit exploitation before official disclosure, though this is not confirmed. Organizations running exposed NetScaler appliances face a window of risk with no patch yet available, which could pressure some to take devices offline preemptively.
- Two new unpatched Citrix NetScaler RCE zero-days are reportedly being exploited.
- Warnings have spread privately through IT suppliers, CERTs, and law enforcement rather than public disclosure.
- Patches are expected next week, separate from the previously disclosed CVE-2026-19490 and CVE-2026-19489.
Source: bleepingcomputer.com, 2026-09-27
Published there as: “Citrix admins warned to shut down NetScalers over 2 exploited zero-days”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.