Recent discoveries have unveiled two critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway devices, which are currently being exploited by cyber attackers. These unpatched flaws, discovered by cybersecurity firm watchTowr on September 26, raise significant concerns for enterprise networks.
Citrix’s Response and Administrator Actions
As of now, Citrix has neither acknowledged these vulnerabilities nor provided a timeline for a fix. This uncertainty has led some network administrators to shut down their devices as a precautionary measure, prioritizing security over operational continuity.
These NetScaler appliances are crucial for managing VPNs, load balancing, and user authentication at network peripheries, making their security paramount. The current vulnerabilities differ from the previously addressed authentication bypass flaw, CVE-2026-19490, which was patched on August 19.
Insights from watchTowr and Community Reactions
watchTowr highlighted the seriousness of these unpatched vulnerabilities through initial social media alerts, citing credible information despite a lack of detailed technical data. The firm anticipated Citrix’s communication and patches to emerge shortly after September 28.
The lack of official guidance has led to varied responses across online communities, such as Reddit, where administrators reported advice to disconnect affected devices immediately. The source of these warnings remains unverified, contributing to the overall uncertainty faced by network operators.
Mitigation Strategies and Future Outlook
Without an official fix, organizations are left to decide between keeping their systems online, isolating them, or powering them down, with the understanding that prior exploitation might have already compromised their security.
Citrix’s existing recommendations for suspected breaches include preserving evidence, isolating compromised devices, and changing credentials. Additionally, the Dutch National Cyber Security Center’s 2025 scripts offer a method to detect signs of compromise, although they come with limitations.
As the situation evolves, the cybersecurity community eagerly awaits Citrix’s next steps, especially as some NetScaler versions near their maintenance end dates. The lack of timely updates from Citrix intensifies the need for vigilance and proactive security measures among users.
