Citrix NetScaler unpatched RCE zero-days actively exploited remote code execution flaw
Vulnerability
Summary
Hide ▲
Show ▼
Two Citrix NetScaler remote code execution zero-days are being exploited in the wild, putting exposed appliances at immediate risk before fixes arrive. Private warnings from suppliers, CERTs, law enforcement, and cybersecurity agencies prompted organizations to shut down or restrict exposure on affected systems. The flaws were found during incident response forensics, and patches were expected early next week. No public CVEs or official mitigation guidance were available when the warnings circulated.
Related Happenings
Citrix NetScaler ADC and NetScaler Gateway unpatched zero-day RCE flaws remote code execution flaw
Vulnerability
H score34
First: 27.09.2026 10:47
Last: 27.09.2026 10:47
Sources 1
About this happening:
Citrix NetScaler ADC and NetScaler Gateway are affected by two unpatched zero-day RCE flaws that are actively exploited in the wild, putting edge appliances used f...
Citrix NetScaler ADC and NetScaler Gateway unpatched zero-day RCE flaws remote code execution flaw
VulnerabilityAbout this happening: Citrix NetScaler ADC and NetScaler Gateway are affected by two unpatched zero-day RCE flaws that are actively exploited in the wild, putting edge appliances used f...
Citrix NetScaler urgent patch guidance for CVE-2026-19490
Advisory/Mitigation
H score54
First: 04.09.2026 18:25
Last: 04.09.2026 18:25
Sources 1
About this happening:
Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...
Citrix NetScaler urgent patch guidance for CVE-2026-19490
Advisory/MitigationAbout this happening: Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...
Citrix NetScaler authentication bypass (CVE-2026-19490)
Vulnerability
H score29
First: 04.09.2026 18:25
Last: 04.09.2026 18:25
Sources 1
About this happening:
CVE-2026-19490 is now being actively probed in the wild, putting exposed Citrix NetScaler appliances at risk of remote authentication bypass. Previdian observe...
Citrix NetScaler authentication bypass (CVE-2026-19490)
VulnerabilityAbout this happening: CVE-2026-19490 is now being actively probed in the wild, putting exposed Citrix NetScaler appliances at risk of remote authentication bypass. Previdian observe...
Citrix NetScaler ADC/Gateway memory overflow flaw (CVE-2026-8452)
Vulnerability
H score34
First: 27.08.2026 12:16
Last: 27.08.2026 12:16
Sources 1
About this happening:
CVE-2026-8452 is an actively exploited memory overflow flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, including systems configured with Gateway V...
Citrix NetScaler ADC/Gateway memory overflow flaw (CVE-2026-8452)
VulnerabilityAbout this happening: CVE-2026-8452 is an actively exploited memory overflow flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, including systems configured with Gateway V...
CISA KEV order for CVE-2026-3055 on Citrix appliances
Public Sector Action
H score34
First: 31.03.2026 10:05
Last: 31.03.2026 10:05
Sources 1
About this happening:
CISA added CVE-2026-3055 to the KEV Catalog and ordered FCEB agencies to secure Citrix NetScaler appliances by Thursday, April 2, turning an actively exploit...
CISA KEV order for CVE-2026-3055 on Citrix appliances
Public Sector ActionAbout this happening: CISA added CVE-2026-3055 to the KEV Catalog and ordered FCEB agencies to secure Citrix NetScaler appliances by Thursday, April 2, turning an actively exploit...
Timeline
-
27.09.2026 19:02 2 articles · 2h ago
Citrix NetScaler administrators are told to shut down appliances after zero-day RCE alerts
Initial DisclosureCitrix NetScaler administrators and customers worldwide received private warnings from IT suppliers, CERTs, law enforcement, and cybersecurity agencies that two unpatched remote code execution zero-days were being exploited in the wild, while watchTowr and the Dutch NCSC-NL said Citrix was preparing patches expected early next week and had not yet assigned CVEs or published IoCs.
Show sources
- Citrix admins warned to shut down NetScalers over 2 exploited zero-days — www.bleepingcomputer.com — 27.09.2026 19:02
- Citrix admins warned to shut down NetScalers over 2 exploited zero-days — www.bleepingcomputer.com — 27.09.2026 19:02