Two Citrix NetScaler Zero-Days Are Being Exploited Right Now and There Is No Patch

Researchers at watchTowr say attackers are already breaking into unpatched NetScaler boxes. Citrix has not shipped a fix.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Full-frame edge-to-edge photoreal editorial shot of a dimly lit server rack in a corporate data center, warm amber status LEDs glowing on a network appliance at
Share

Key points

  • Researchers at watchTowr disclosed on September 26 that two unpatched flaws in Citrix NetScaler ADC and NetScaler Gateway are being exploited in the wild, with no vendor fix available.
  • The bugs allow remote code execution, meaning an attacker on the internet can run their own commands on the appliance without logging in.
  • Citrix has not publicly confirmed the two zero-day flaws watchTowr is tracking, and has not issued a patch for them.
  • Some administrators have pulled their NetScaler appliances offline rather than leave them exposed while waiting for a patch.
  • NetScaler gear sits at the front door of banks, hospitals and government networks, handling logins and remote access for staff.

Two fresh holes in Citrix NetScaler are being attacked right now, and there is no patch.

That is the warning from watchTowr, the exposure-management firm run by Benjamin Harris, which published its findings on September 26. Attackers can trigger both bugs without a username or password, then run code of their choosing on the device. Pre-authentication remote code execution, in the jargon: a stranger on the internet takes over the box.

NetScaler ADC and NetScaler Gateway are appliances that sit between the public internet and a company's internal systems. They handle staff logins and remote access for web apps. Banks, hospitals and government agencies run them by the thousand. When one is breached, the attacker is already inside the perimeter.

Citrix, now part of Cloud Software Group, has not confirmed the two flaws watchTowr is tracking and has not shipped a fix. We reported on 17 September that CISA had already ordered federal agencies to patch a separate critical NetScaler flaw, confirming active exploitation of CVE-2026-19490. What watchTowr is now describing is different and still unpatched.

What are the two new flaws?

Both are remote code execution bugs reachable before login. WatchTowr's writeup, headlined "You're back in the room," is a deliberate nod to the fact that NetScaler admins have lived through this exact scenario before. CitrixBleed in 2023 and CitrixBleed 2 earlier this year both saw ransomware crews chain into NetScaler appliances within days of disclosure.

WatchTowr has withheld full technical detail while Citrix works on a patch. The firm says exploitation is already happening.

What should defenders do now?

Assume exposure until Citrix ships a fix. Some administrators are taking appliances offline entirely rather than leave them reachable from the internet. That is a drastic call, because pulling a NetScaler usually means killing staff remote access, but it's the only guaranteed mitigation while there is no patch.

For those who can't yank the box, the practical steps are unglamorous: restrict the management interface to trusted addresses, capture and preserve NetScaler logs off the device, then hunt for the indicators of compromise watchTowr and Citrix will publish once a fix lands. Attackers rarely limit themselves to one bug when they're already probing a target, so apply any available patches for previously disclosed NetScaler flaws now if you haven't.

Should ordinary customers worry?

Not directly, but the ripple effects reach everyone. If your bank or hospital uses NetScaler for staff remote access, a breach here is how criminals get in the door before they touch your data. Watch for the usual after-effects over the coming weeks: breach notifications, forced password resets, and phishing emails referencing services you actually use.

My read: Citrix has had a rough run with NetScaler, and ransomware crews have the tooling for this appliance already dialled in. The patch, whenever it arrives, will be reverse-engineered and weaponised fast. Patch the moment it lands, or unplug now.

© 2026 Threat Vectr