Exploit

Active Exploitation of Citrix NetScaler Zero-Day RCE Vulnerabilities

September 26, 2026

Cybersecurity

Exploit

Key Facts

Signal Type

Exploit

Industry

Cybersecurity

Companies

Citrix, watchTowr

Date

September 26, 2026

What Happened

Two unpatched remote code execution zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances are being actively exploited in the wild, as reported by security firm watchTowr. No official patch or advisory from Citrix has been issued, prompting recommendations to take affected systems offline to prevent compromise.

Who Is Affected

Organizations using Citrix NetScaler ADC and Gateway are at immediate risk. The Dutch National Cyber Security Centre (NCSC) has confirmed multiple organizations in the Netherlands have been compromised. Without a patch, all deployments of these appliances are vulnerable.

Market Impact

This active exploitation creates urgent demand for incident response, vulnerability management, and network segmentation services. Organizations need immediate assistance to:

  • Restrict access to affected appliances
  • Monitor for indicators of compromise
  • Prepare for emergency patching once Citrix releases a fix

Vendors offering EDR, patch management, and security consulting can reach affected enterprises this week while attention is heightened.

What to Watch

Citrix is expected to release an emergency patch soon. No CVE identifiers have been assigned yet for these vulnerabilities, which are distinct from previously patched issues like CVE-2026-19490. Administrators should monitor official Citrix advisories and watchTowr for updates on exploitation indicators.

Related coverage

Get cybersecurity signals in your CRM

Data breaches, ransomware events, funding rounds, and M&A across security vendors and targets.

Book a 15 min call
Dominykas Rukas - Revenanas