Citrix NetScaler ADC and NetScaler Gateway unpatched zero-day RCE flaws remote code execution flaw
Vulnerability
Summary
Hide ▲
Show ▼
Citrix NetScaler ADC and NetScaler Gateway are affected by two unpatched zero-day RCE flaws that are actively exploited in the wild, putting edge appliances used for VPN and remote access at immediate compromise risk.
Related Happenings
Citrix NetScaler urgent patch guidance for CVE-2026-19490
Advisory/Mitigation
H score54
First: 04.09.2026 18:25
Last: 04.09.2026 18:25
Sources 1
About this happening:
Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...
Citrix NetScaler urgent patch guidance for CVE-2026-19490
Advisory/MitigationAbout this happening: Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...
Citrix NetScaler authentication bypass (CVE-2026-19490)
Vulnerability
H score29
First: 04.09.2026 18:25
Last: 04.09.2026 18:25
Sources 1
About this happening:
CVE-2026-19490 is now being actively probed in the wild, putting exposed Citrix NetScaler appliances at risk of remote authentication bypass. Previdian observe...
Citrix NetScaler authentication bypass (CVE-2026-19490)
VulnerabilityAbout this happening: CVE-2026-19490 is now being actively probed in the wild, putting exposed Citrix NetScaler appliances at risk of remote authentication bypass. Previdian observe...
Citrix NetScaler ADC/Gateway memory overflow flaw (CVE-2026-8452)
Vulnerability
H score34
First: 27.08.2026 12:16
Last: 27.08.2026 12:16
Sources 1
About this happening:
CVE-2026-8452 is an actively exploited memory overflow flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, including systems configured with Gateway V...
Citrix NetScaler ADC/Gateway memory overflow flaw (CVE-2026-8452)
VulnerabilityAbout this happening: CVE-2026-8452 is an actively exploited memory overflow flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, including systems configured with Gateway V...
CISA KEV order for CVE-2026-3055 on Citrix appliances
Public Sector Action
H score34
First: 31.03.2026 10:05
Last: 31.03.2026 10:05
Sources 1
About this happening:
CISA added CVE-2026-3055 to the KEV Catalog and ordered FCEB agencies to secure Citrix NetScaler appliances by Thursday, April 2, turning an actively exploit...
CISA KEV order for CVE-2026-3055 on Citrix appliances
Public Sector ActionAbout this happening: CISA added CVE-2026-3055 to the KEV Catalog and ordered FCEB agencies to secure Citrix NetScaler appliances by Thursday, April 2, turning an actively exploit...
Cloud Software Group NetScaler urgent remediation advisory
Advisory/Mitigation
H score44
First: 25.03.2026 17:52
Last: 25.03.2026 17:52
Sources 1
About this happening:
Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...
Cloud Software Group NetScaler urgent remediation advisory
Advisory/MitigationAbout this happening: Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...
Latest development: 31.07.2026 20:35
Unit 42 confirmed three successful compromises of Citrix NetScaler systems via CVE-2026-3055, with the threat actor extracting memory and searching for authentication cookies to hijack sessions, while also conducting manual attacks against more than 460 systems using vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products.
Timeline
-
26.09.2026 03:00 2 articles · 1d ago
watchTowr flags two actively exploited NetScaler RCE zero-days
Initial DisclosurewatchTowr said two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances were being actively exploited in the wild on September 26. It later described both flaws as remote code execution bugs, said they were exploited before any fix existed, and said they were discovered during forensic investigations; Citrix had not confirmed the flaws or published a fix.
Show sources
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation — thehackernews.com — 27.09.2026 10:47
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation — thehackernews.com — 27.09.2026 10:47
-
26.09.2026 03:00 1 articles · 1d ago
Administrators take NetScaler appliances offline after shutdown advice
Untyped PhaseSome administrators shut down or isolated Citrix NetScaler appliances after receiving advice to take them offline immediately, and Citrix's existing suspected-compromise guidance calls for preserving evidence, isolating the appliance, changing service account passwords and stored secrets, revoking certificates and private keys, and keeping the management interface off the public internet.
Show sources
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation — thehackernews.com — 27.09.2026 10:47