Vulnerabilities · 4h ago
watchTowr says two unpatched remote code execution zero-days in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited, and Citrix has not yet published a bulletin or fix. Some administrators have already taken appliances offline rather than leave the edge boxes exposed.
The flaw matters because NetScaler sits in front of VPN, remote access, load balancing, and authentication. In plain terms, the front-door appliance itself is the attack surface, so an exploit can give an intruder a foothold at the network boundary while keeping essential access services in the blast radius.
For teams that use NetScaler as the trust gate for internet-facing access, this is a service-disruption story as much as a compromise story. Until Citrix publishes fixes or mitigation guidance, patch-and-move-on is not the whole playbook, and a clean update would not prove an attacker was absent before the fix landed.
2 sources covering this story
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
watchTowr says two unpatched NetScaler RCE flaws were exploited before fixes, while Citrix has yet to publish a bulletin or patch.
Citrix NetScaler Zero-Day RCE vulnerabilities: FAQ
Two zero-day RCE vulnerabilities in Citrix NetScaler are reportedly exploited in the wild.
Part of the PlainSec briefing for 2026-09-27