Citrix NetScaler administrators are confronting reports of two undisclosed remote code execution vulnerabilities allegedly exploited in real-world attacks.
watchTowr said the flaws are unpatched zero-days, were identified during forensic investigations, and that Citrix communications and fixes are expected early next week. However, Citrix had not published technical details, CVE identifiers, affected builds, indicators of compromise, or an advisory for these reported flaws at the time of writing, leaving defenders to make high-impact decisions with limited verified information.
The warning began with reports that multiple unpatched NetScaler RCE vulnerabilities were circulating in the wild. watchTowr described the intelligence as credible and later stated that two separate vulnerabilities can enable remote code execution.
The company has not publicly disclosed exploitation paths, prerequisites, payloads, or forensic artifacts, making independent validation difficult. Treat the claims as a serious warning, not yet a fully vendor-confirmed disclosure.
Some organizations reportedly responded by shutting down internet-exposed NetScaler appliances. Such action can interrupt VPN access, application delivery, authentication, and other critical services, yet edge appliances occupy a privileged position at the network boundary.
If defenders cannot patch or reliably mitigate a potentially exploitable RCE flaw, temporarily removing exposed systems from service may be the safer decision, particularly for sensitive environments.
The emerging alert must not be confused with Citrix’s August 19 bulletin covering CVE-2026-19490 and CVE-2026-19489. CVE-2026-19490 is a critical authentication-bypass flaw rated 9.3 under CVSS v4.0; it affects certain customer-managed NetScaler Gateway and AAA virtual-server configurations.
CVE-2026-19489, rated 8.8, is a memory-overflow issue requiring SIP ALG on a Large Scale NAT group and can cause unpredictable behavior or denial of service.

Active exploitation of CVE-2026-19490 is already established. Singapore’s Cyber Security Agency warned on September 7 that exploitation attempts had been observed, while CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 9. Canada’s Cyber Center subsequently urged emergency patching and monitoring for unauthorized access.
Those facts fueled uncertainty over whether the latest alarm concerned the known authentication bypass or genuinely new zero-days; watchTowr’s later wording explicitly characterized the reported issues as two unpatched RCE flaws.
For the August vulnerabilities, Citrix advises upgrading NetScaler ADC and Gateway 14.1 to 14.1-73.32 or later and 13.1 to 13.1-63.21 or later. Fixed baselines for specialized editions are 14.1-73.32 FIPS and 13.1-37.277 for FIPS or NDcPP. Citrix lists no workaround for those flaws, and its bulletin applies to customer-managed appliances rather than Citrix-managed cloud services.
Until Citrix clarifies the new RCE reports, defenders should inventory every NetScaler instance, confirm exact builds and exposure, restrict management access, and place compensating controls before public interfaces.
Security teams should preserve logs and forensic images, review authentication events, new sessions, configuration changes, unexpected processes, suspicious files, and anomalous outbound connections, and avoid wiping potentially compromised devices before collecting evidence.
Organizations unable to accept the residual risk should isolate or shut down exposed appliances under an approved business-continuity process. Teams should also monitor Citrix’s security bulletin channel for patches and deployment guidance rather than relying on social-media fragments alone.
The episode again shows why internet-facing remote-access infrastructure demands rapid asset discovery, tested emergency patching, centralized logging, and rehearsed incident-response procedures, especially when defenders must act before complete technical disclosure arrives.