Citrix shops running NetScaler ADC and NetScaler Gateway have no patch for two unpatched remote code execution bugs that a security firm says are already being exploited.
watchTowr flagged the pair on September 26. Both are remote code execution flaws, neither is patched, and the exploitation predates any fix, the firm said. Citrix has not confirmed the bugs or published a bulletin, and it has not said which builds will receive one.
The two are distinct from CVE-2026-19490, an authentication bypass Citrix patched on August 19 that later landed on CISA’s Known Exploited Vulnerabilities list.
NetScaler appliances sit at the network edge, terminating VPN, remote access, authentication, and load balancing, so a working edge bug is a short path into an enterprise.
Administrators discussed taking devices offline instead of waiting. One wrote on Reddit that a supplier’s security team phoned to urge an immediate shutdown, without giving details. Others said they had followed.
The fix, when it arrives, will not answer the question that matters most. Exploitation began before any patch existed, so a later update cannot show whether an intruder already got in. A prior NetScaler zero-day, used against Dutch organizations in 2025, drew the same warning from that country’s cyber agency. Removing an intruder’s foothold takes more than a patch.
Citrix’s own compromise guidance still fits. Snapshot the appliance, pull logs and a support bundle, and dump the packet engine core before touching anything. Then isolate it, rotate every service account password and secret stored on it, reset passwords for users who signed in through it, and revoke its certificates and private keys. Keep the management interface off the internet.
Citrix has also stayed quiet about which branches get the fix. Under the company’s own release schedule, NetScaler 13.1 left end of maintenance on September 15.
