New unpatched Citrix NetScaler zero-days actively exploited, admins told to shut down devices
Citrix administrators report being privately contacted by IT suppliers, law enforcement, and cybersecurity agencies warning of two unpatched NetScaler remote code execution vulnerabilities being exploited in the wild. Security firm watchTowr confirmed the flaws are distinct from CVE-2026-19490 and CVE-2026-19489 disclosed in August, and said patches are expected next week.