Find notable cyber news and cases, enriched with sources, timelines, and signals.

Citrix NetScaler ADC and NetScaler Gateway unpatched zero-day RCE flaws remote code execution flaw

Vulnerability
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

Citrix NetScaler ADC and NetScaler Gateway are affected by two unpatched zero-day RCE flaws that are actively exploited in the wild, putting edge appliances used for VPN and remote access at immediate compromise risk.

Related Happenings

Citrix NetScaler urgent patch guidance for CVE-2026-19490

Advisory/Mitigation
H score54 First: 04.09.2026 18:25 Last: 04.09.2026 18:25 Sources 1

About this happening: Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...

Citrix NetScaler authentication bypass (CVE-2026-19490)

Vulnerability
H score29 First: 04.09.2026 18:25 Last: 04.09.2026 18:25 Sources 1

About this happening: CVE-2026-19490 is now being actively probed in the wild, putting exposed Citrix NetScaler appliances at risk of remote authentication bypass. Previdian observe...

Citrix NetScaler ADC/Gateway memory overflow flaw (CVE-2026-8452)

Vulnerability
H score34 First: 27.08.2026 12:16 Last: 27.08.2026 12:16 Sources 1

About this happening: CVE-2026-8452 is an actively exploited memory overflow flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, including systems configured with Gateway V...

CISA KEV order for CVE-2026-3055 on Citrix appliances

Public Sector Action
H score34 First: 31.03.2026 10:05 Last: 31.03.2026 10:05 Sources 1

About this happening: CISA added CVE-2026-3055 to the KEV Catalog and ordered FCEB agencies to secure Citrix NetScaler appliances by Thursday, April 2, turning an actively exploit...

Cloud Software Group NetScaler urgent remediation advisory

Advisory/Mitigation
H score44 First: 25.03.2026 17:52 Last: 25.03.2026 17:52 Sources 1

About this happening: Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...

Latest development: 31.07.2026 20:35

Unit 42 confirmed three successful compromises of Citrix NetScaler systems via CVE-2026-3055, with the threat actor extracting memory and searching for authentication cookies to hijack sessions, while also conducting manual attacks against more than 460 systems using vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products.

Timeline

  1. 26.09.2026 03:00 2 articles · 1d ago

    watchTowr flags two actively exploited NetScaler RCE zero-days

    Initial Disclosure

    watchTowr said two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances were being actively exploited in the wild on September 26. It later described both flaws as remote code execution bugs, said they were exploited before any fix existed, and said they were discovered during forensic investigations; Citrix had not confirmed the flaws or published a fix.

    Show sources
  2. 26.09.2026 03:00 1 articles · 1d ago

    Administrators take NetScaler appliances offline after shutdown advice

    Untyped Phase

    Some administrators shut down or isolated Citrix NetScaler appliances after receiving advice to take them offline immediately, and Citrix's existing suspected-compromise guidance calls for preserving evidence, isolating the appliance, changing service account passwords and stored secrets, revoking certificates and private keys, and keeping the management interface off the public internet.

    Show sources