Citrix NetScaler: Two Unpatched RCEs Actively Exploited
Two unpatched RCEs in Citrix NetScaler ADC and Gateway are actively exploited in the wild. CVE IDs are pending assignment; Citrix expects patches by end of September 2026.

Security firm watchTowr has confirmed active exploitation of two remote code execution flaws in Citrix NetScaler ADC and NetScaler Gateway, as reported by The Hacker News on September 27, 2026. Neither vulnerability has a CVE ID yet. Neither has a patch.
Citrix has acknowledged the flaws and told customers to expect fixes the week of September 28. Until then, every NetScaler ADC and Gateway appliance is running vulnerable software that attackers are already using.
Why this is worse than a typical pre-patch window
Exploitation started before anyone outside of attackers knew the flaws existed. That sequence matters because patching after the fact does not reveal whether an appliance was already compromised. watchTowr confirmed this through forensic work, not just theoretical analysis. If you patch next week without first investigating for signs of intrusion, you have no reliable way to know whether you’re cleaning up a system that was already hit.
This is the second major NetScaler advisory in six weeks. CVE-2026-19490, an authentication bypass patched August 19 (builds 14.1-73.32 and 13.1-63.21), was later confirmed exploited in early September. Organizations that delayed that patch have compounding exposure now.
What to do before patches arrive
Restrict management access. If NetScaler administrative interfaces are reachable from the internet or untrusted segments, lock them down now. This does not fix the vulnerability but takes the easiest attack path away.
Look for evidence of compromise before you patch. watchTowr’s September 27 disclosure includes guidance on forensic artifacts. Check appliance logs for unusual administrative sessions, unexpected configuration changes, and signs of web shell deployment. Doing this investigation now, while the attacker footprint is fresher, will produce more reliable results than running the same checks after patching.
Treat the patch as P1 when it drops. Citrix has committed to releasing fixes this week. When the advisory goes live, these are unpatched RCEs with confirmed in-the-wild exploitation: apply immediately, do not wait for a maintenance window.
Check prior CVE-2026-19490 patch status. If your appliances are not yet on build 14.1-73.32 or 13.1-63.21, that auth bypass is still open alongside these new flaws. Get current on the prior advisory first.
Current status
- CVE IDs: Pending assignment
- Affected products: Citrix NetScaler ADC and NetScaler Gateway (version ranges unconfirmed by Citrix at time of publication)
- Patch available: No; expected week of September 28, 2026
- Exploitation status: Active in the wild, confirmed by watchTowr forensic investigation
- CISA KEV: Not yet listed; expect an addition if confirmed exploitation continues after patch release
Watch Citrix’s security advisory feed directly for patch release details. The watchTowr disclosure with forensic guidance is covered in the The Hacker News writeup.
For broader context on recent NetScaler activity, see CISA KEV: Cisco, Citrix, Fortinet Added September 12.
Found this useful? Share it.


