Vulnerabilities & Exploits · Zero-Day Exploit

Citrix NetScaler Zero-Days Force Edge Shutdowns

watchTowr says two unpatched remote code execution zero-days in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited, and Citrix has not yet published a bulletin or fix. Some administrators have already taken appliances offline rather than leave the edge boxes exposed.

The flaw matters because NetScaler sits in front of VPN, remote access, load balancing, and authentication. In plain terms, the front-door appliance itself is the attack surface, so an exploit can give an intruder a foothold at the network boundary while keeping essential access services in the blast radius.

For teams that use NetScaler as the trust gate for internet-facing access, this is a service-disruption story as much as a compromise story. Until Citrix publishes fixes or mitigation guidance, patch-and-move-on is not the whole playbook, and a clean update would not prove an attacker was absent before the fix landed.

2 sources · 5h ago

Timeline

Sources

Vendor digest: Citrix

Part of the PlainSec briefing for 2026-09-27

Every edition of this story: Citrix NetScaler Zero-Days Force Edge Shutdowns

More from today