Citrix NetScaler users are currently grappling with reports of two remote code execution (RCE) vulnerabilities that are being actively exploited in attacks. These vulnerabilities, described as zero-day flaws, have yet to be patched, causing significant concern among cybersecurity experts.
Unpatched Vulnerabilities Raise Concerns
According to watchTowr, these vulnerabilities were discovered during forensic investigations and are yet to receive official communication or fixes from Citrix. As of now, Citrix has not provided technical specifics, CVE identifiers, or details regarding the affected builds, leaving security teams with limited information to act upon.
Initial warnings suggested multiple unpatched RCE vulnerabilities were in circulation. watchTowr confirmed that two distinct vulnerabilities could allow remote code execution, although the specifics of exploitation paths and prerequisites remain undisclosed. This lack of detailed information has made independent verification challenging.
Impact on Organizations
In response to these reports, some organizations have opted to shut down internet-exposed NetScaler appliances. While this move can disrupt critical services like VPN access and application delivery, it is seen as a necessary precaution for sensitive environments where patching is not immediately possible.
The current alert should not be confused with Citrix’s previous advisory issued on August 19, which addressed two other vulnerabilities. These earlier vulnerabilities, CVE-2026-19490 and CVE-2026-19489, had their own set of implications and required specific action from administrators.
Advice for Security Teams
Until Citrix provides more information on the new RCE vulnerabilities, security teams are advised to assess all NetScaler instances, confirm their builds, and restrict management access. It’s crucial to implement compensating controls to safeguard public interfaces.
Organizations should preserve logs, review authentication events, and monitor for any unusual activity. In cases where the risk cannot be managed, isolating affected devices may be necessary. Keeping abreast of updates from Citrix’s security bulletin channel is also recommended.
This situation underscores the need for rapid asset discovery and emergency patching protocols for internet-facing infrastructure. Organizations must be prepared to act swiftly, even before full technical disclosures are available, to protect their systems against potential threats.
