Unpatched zero-days under active exploitation: 2 (Source: watchTowr via X, cited by The Hacker News (September 27, 2026))
Security firm watchTowr said on September 26 that it has identified two new, unpatched remote-code-execution vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that are already being exploited. Citrix has not confirmed the flaws or published a fix, and some administrators have taken their appliances offline rather than wait for one. NetScaler devices sit at the network edge, handling VPN access, load balancing, and user authentication for enterprises, which is why a flaw with no available patch forces an immediate operational decision rather than a scheduling one.
Two flaws, no bulletin, no confirmed timeline
watchTowr's account, posted on X and expanded in a follow-up at 22:19 UTC on September 26, describes two RCE vulnerabilities exploited before any fix existed, discovered during forensic investigations. The firm said Citrix communications and a patch are expected early in the week of September 28, but it has published no evidence, named no victim, and has not identified whose forensic work found the exploitation. Citrix has not said whether the current builds, 14.1-73.32 and 13.1-63.21, or any newer release, are affected.
A separate, already-patched flaw shows the stakes
The new vulnerabilities are distinct from CVE-2026-19490, an authentication bypass Citrix patched on August 19 that CISA added to its Known Exploited Vulnerabilities catalog on September 9. A fix for that flaw has existed for over a month, unlike the two new ones. watchTowr's description of the new flaws — exploited before any fix existed — means that when Citrix does ship a patch, installing it will not tell an operator whether an attacker already gained access.
Shutdown reports, and a 2025 precedent
Reports of shutdown advice appeared on Reddit's r/Citrix forum the same day; one administrator wrote that an IT supplier's security team had phoned to recommend powering down NetScalers immediately, without providing details, and others in the thread reported similar calls. The source of that advice has not been established, and no indicators of compromise for the new flaws have been published. Citrix's existing incident guidance for a suspected NetScaler compromise calls for preserving a VPX snapshot, remote syslog and NetScaler Console logs, a support bundle, and a core dump of the packet engine, then rotating every credential and certificate stored on the device, and states plainly that management interfaces should never be exposed to the public internet. In 2025, after a separate NetScaler zero-day was used against Dutch organizations, the Netherlands' National Cyber Security Center said updating alone did not remove risk, because an attacker could retain access gained before the patch, and it published check scripts covering live appliances, core dumps, and full NetScaler images.
What to ask your team
With NetScaler 13.1 past its maintenance window as of September 15 and Citrix silent on whether it will patch the new flaws on that branch at all, budget-holders running NetScaler ADC or Gateway should ask three questions now: which exact build is deployed on every appliance, whether the management interface is reachable from the public internet given Citrix's own guidance that it never should be, and whether VPX snapshots, syslog, NetScaler Console logs, and core dumps are being preserved today — before any patch ships — so a compromise that predates the fix can still be investigated afterward.





