Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Two zero-day remote code execution vulnerabilities in Citrix NetScaler ADC/Gateway are under active exploitation in the wild with no patches available. The discovery, announced Sept. 26, 2026 by security firm watchTowr, triggered recommendations from some IT providers to immediately power down appliances, citing the Dutch NCSC-NL as their source.
- Two zero-day RCE vulnerabilities in Citrix NetScaler are actively exploited in the wild with no assigned CVEs or patches.
- watchTowr uncovered the exploitation during forensic investigations; Citrix has indicated patches and an advisory are expected early the week of Sept. 26, 2026.
- Some administrators received immediate shutdown recommendations from IT providers citing NCSC-NL, corroborated on Reddit threads.
- watchTowr explicitly denied the two new zero-days are the same as CVE-2026-19490, an authentication bypass vulnerability patched Aug. 19, 2026.
"Two unpatched remote code execution vulnerabilities in Citrix NetScaler have been exploited in the wild as zero-days, security firm watchTowr said on Saturday, as organisations take appliances offline ahead of patches Citrix is expected to release early next week."
Forensic Discovery and Citrix Silence
watchTowr announced the discovery on Sept. 26, 2026 via an X post: "Two unpatched remote code execution vulnerabilities in Citrix NetScaler have been exploited in the wild as zero-days." The firm clarified the exploitation surfaced during forensic investigations, not lab testing.
According to the same source, Citrix expects to release communications and patches "early next week" — after the weekend of Sept. 26-27. The exact technical mechanism of the two vulnerabilities has not been disclosed. It is unknown which NetScaler ADC/Gateway builds are affected.
Shutdown Recommendations and Reddit Trail
Running parallel to watchTowr's announcement, a Reddit thread titled "Netscaler leak?" on r/Citrix garnered over 75 upvotes and more than 50 comments. User FastFredNL reported their IT provider had received information "directly from NCSC-NL" with a recommendation for "immediate shutdown," summarized as: "this is a big one and there's no fix yet, shut it down."
Other administrators confirmed they had powered down NetScaler appliances based on notifications traceable to NCSC-NL. This brief contains no official confirmation from NCSC-NL or Citrix of the shutdown recommendation at time of writing.
CVE-2026-19490: The Unrelated Bug
A clear distinction emerges from the brief: the two new zero-day RCEs do not coincide with CVE-2026-19490. watchTowr responded on X to those conflating the vulnerabilities: "the new issue is a different vulnerability."
CVE-2026-19490 is an authentication bypass bug with a CVSS 9.3 score, added to the CISA KEV catalog on Sept. 9, 2026, with patches available since Aug. 19, 2026 (builds 14.1-73.32 and 13.1-63.21). It is unknown whether these builds are vulnerable to the two new zero-day RCEs.
Immediate Actions
Organizations running Citrix NetScaler ADC/Gateway appliances should verify whether they have received direct communications from IT providers or government agencies with shutdown recommendations. Those without specific guidance should monitor Citrix advisories expected early the week of Sept. 26, 2026.
It is not possible to assess the effectiveness of unofficial temporary mitigations: the brief documents no verified IP restrictions, port blocks, or other countermeasures. watchTowr has not published sufficient technical details to evaluate attack surfaces or indicators of compromise.
Organizations should note the historical pattern of NCSC-NL includes shutdown recommendations for zero-day RCEs on internet-exposed appliances, as occurred in 2020 for CVE-2019-19781. This context, while not proof of the current situation, explains the origin of the guidance some administrators received.
Frequently Asked Questions
- When will patches arrive for the two zero-day RCEs?
- According to watchTowr, Citrix has communicated that patches and an advisory are expected early the week of Sept. 26, 2026. It is unknown whether this timeline covers both vulnerabilities or only one.
- Are there CVEs assigned to the two new zero-days?
- No. watchTowr has not named CVE IDs for the two RCE vulnerabilities. The brief reports no assignments from NVD, CVE.org, or Citrix advisories.
- Are builds 14.1-73.32 and 13.1-63.21, which fix CVE-2026-19490, safe?
- The brief does not specify. It is unknown whether these builds are vulnerable to the two new zero-day RCEs.
NCSC-NL Historical Context
NCSC-NL has documented precedents for drastic recommendations on exposed Citrix appliances. In 2020, the Dutch agency advised shutting down Citrix ADC/Gateway during the handling of CVE-2019-19781, an RCE vulnerability subsequently widely exploited. In 2025, NCSC-NL sent confidential alerts on CVE-2025-6543 before confirming zero-day exploitation.
This historical pattern, combined with the inherent severity of RCE vulnerabilities on perimeter appliances, explains why some IT providers transmitted immediate recommendations even absent public official advisories. The decision to power down critical appliances before patch availability remains an organizational risk assessment.
Limits and Uncertainties
The absence of details on affected versions, attack vectors, and indicators of compromise limits the capacity for targeted response until Citrix releases advisories. watchTowr has not published technical mechanisms, proof-of-concept code, or attribution to specific threat actors. The scale of exploitation and number of compromised organizations are unknown.
Organizations must await official communications from Citrix for patched builds, mitigating configurations, and verified indicators of compromise. Until then, verifying any direct communications from IT providers or government agencies remains the only documented action in this brief.
Information is based on cited sources and current as of publication.
Sources
- https://www.cyberkendra.com/2026/09/netscaler-shutdown-warning-unverified-rce-flaws.html
- https://tech-insider.org/citrix-netscaler-cisa-kev-22000-exposed-2026/
- https://nvd.nist.gov/vuln/detail/cve-2026-19490
- https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild
- https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild
- https://www.cve.org/CVERecord?id=CVE-2026-85706
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search=CVE-2026-76461&field_date_added_wrapper=all&field_cve=&sort_by=field_date_added&items_per_page=20&url=
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.