Find notable cyber news and cases, enriched with sources, timelines, and signals.

Citrix NetScaler unpatched RCE zero-days actively exploited remote code execution flaw

Vulnerability
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

Two Citrix NetScaler remote code execution zero-days are being exploited in the wild, putting exposed appliances at immediate risk before fixes arrive. Private warnings from suppliers, CERTs, law enforcement, and cybersecurity agencies prompted organizations to shut down or restrict exposure on affected systems. The flaws were found during incident response forensics, and patches were expected early next week. No public CVEs or official mitigation guidance were available when the warnings circulated.

Related Happenings

Citrix NetScaler ADC and NetScaler Gateway unpatched zero-day RCE flaws remote code execution flaw

Vulnerability
H score34 First: 27.09.2026 10:47 Last: 27.09.2026 10:47 Sources 1

About this happening: Citrix NetScaler ADC and NetScaler Gateway are affected by two unpatched zero-day RCE flaws that are actively exploited in the wild, putting edge appliances used f...

Citrix NetScaler urgent patch guidance for CVE-2026-19490

Advisory/Mitigation
H score54 First: 04.09.2026 18:25 Last: 04.09.2026 18:25 Sources 1

About this happening: Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...

Citrix NetScaler authentication bypass (CVE-2026-19490)

Vulnerability
H score29 First: 04.09.2026 18:25 Last: 04.09.2026 18:25 Sources 1

About this happening: CVE-2026-19490 is now being actively probed in the wild, putting exposed Citrix NetScaler appliances at risk of remote authentication bypass. Previdian observe...

Citrix NetScaler ADC/Gateway memory overflow flaw (CVE-2026-8452)

Vulnerability
H score34 First: 27.08.2026 12:16 Last: 27.08.2026 12:16 Sources 1

About this happening: CVE-2026-8452 is an actively exploited memory overflow flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, including systems configured with Gateway V...

CISA KEV order for CVE-2026-3055 on Citrix appliances

Public Sector Action
H score34 First: 31.03.2026 10:05 Last: 31.03.2026 10:05 Sources 1

About this happening: CISA added CVE-2026-3055 to the KEV Catalog and ordered FCEB agencies to secure Citrix NetScaler appliances by Thursday, April 2, turning an actively exploit...

Timeline

  1. 27.09.2026 19:02 2 articles · 2h ago

    Citrix NetScaler administrators are told to shut down appliances after zero-day RCE alerts

    Initial Disclosure

    Citrix NetScaler administrators and customers worldwide received private warnings from IT suppliers, CERTs, law enforcement, and cybersecurity agencies that two unpatched remote code execution zero-days were being exploited in the wild, while watchTowr and the Dutch NCSC-NL said Citrix was preparing patches expected early next week and had not yet assigned CVEs or published IoCs.

    Show sources