Exploit
Active Exploitation of Citrix NetScaler Zero-Day RCE Vulnerabilities
Key Facts
Signal Type
Exploit
Industry
Cybersecurity
Companies
Citrix, watchTowr
Date
September 26, 2026
Two unpatched remote code execution zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances are being actively exploited in the wild, as reported by security firm watchTowr. No official patch or advisory from Citrix has been issued, prompting recommendations to take affected systems offline to prevent compromise.
Organizations using Citrix NetScaler ADC and Gateway are at immediate risk. The Dutch National Cyber Security Centre (NCSC) has confirmed multiple organizations in the Netherlands have been compromised. Without a patch, all deployments of these appliances are vulnerable.
This active exploitation creates urgent demand for incident response, vulnerability management, and network segmentation services. Organizations need immediate assistance to:
Vendors offering EDR, patch management, and security consulting can reach affected enterprises this week while attention is heightened.
Citrix is expected to release an emergency patch soon. No CVE identifiers have been assigned yet for these vulnerabilities, which are distinct from previously patched issues like CVE-2026-19490. Administrators should monitor official Citrix advisories and watchTowr for updates on exploitation indicators.
Source:
ThreatCluster Threat FeedGet cybersecurity signals in your CRM
Data breaches, ransomware events, funding rounds, and M&A across security vendors and targets.
