On 26 September 2026, watchTowr reported two alleged unpatched remote code execution (RCE) vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway which, according to the company, are already being exploited by threat actors. As of the time of publication, Citrix has not confirmed the existence of these vulnerabilities and has not released an advisory or a patch. Administrators using NetScaler on the network perimeter for VPN, load balancing and authentication need to assess the risks and decide whether to continue operating the devices, isolate them, or shut them down until official information appears.
What exactly watchTowr is claiming
In its first post, watchTowr stated that it was responding to rumors about several unpatched NetScaler RCE vulnerabilities, calling the information “credible”. In a subsequent post, the company clarified that it is talking about two vulnerabilities, both allowing remote code execution, both unpatched, discovered during forensic investigations, and that patches and communications from Citrix are expected in the week starting 28 September.
It is important to emphasize the limitations of this information: watchTowr has not published technical evidence, has not named any affected organizations, and has not indicated whose forensic investigations identified the exploitation. The alleged vulnerabilities do not have CVE identifiers, CVSS scores, a list of affected versions or indicators of compromise. Neither CISA, nor NVD, nor Citrix itself confirms the existence of these vulnerabilities. Thus, the statement remains a single-source claim without independent confirmation.
Distinguishing from known vulnerabilities
The reported vulnerabilities are not previously fixed issues. On 19 August 2026, Citrix released a security advisory addressing CVE-2026-19490 — an authentication bypass via alternate path (CWE-288) with a CVSS v4.0 score of 9.3. This vulnerability affects configurations with Gateway or AAA virtual servers under certain SAML conditions and requires upgrading to versions 14.1-73.32 or 13.1-63.21 and later. CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog on 9 September 2026.
Earlier, on 30 June 2026, Citrix patched CVE-2026-8452 — a buffer overflow vulnerability (CWE-119, CVSS v4.0 8.8), which the vendor describes as leading to unpredictable behavior and denial of service. In August, watchTowr demonstrated that this vulnerability can be used for remote code execution, although Citrix does not officially classify it as RCE. We have already covered this vulnerability in the context of its addition to the CISA KEV catalog.
Since patches exist for both known CVEs and watchTowr explicitly states that there are no fixes for the new vulnerabilities, this must be about other, as yet unidentified issues.
Community reaction
On the same day, posts appeared on Reddit (r/Citrix) from administrators whose IT providers had recommended immediately shutting down NetScaler devices without giving any details. Several participants confirmed receiving similar recommendations from their providers. The source of these warnings has not been established.
Impact assessment
NetScaler ADC and NetScaler Gateway are perimeter devices that provide VPN access, load balancing and user authentication. Compromise of such a device can potentially give an attacker access to the internal network, user credentials and certificates.
An additional factor of uncertainty: NetScaler 13.1 reached End of Maintenance on 15 September 2026, according to the Citrix lifecycle schedule. Citrix has not said whether this branch will receive fixes for the alleged new vulnerabilities.
Practical recommendations
Since there are no patches for the reported vulnerabilities and no indicators of compromise have been published, the standard “patch and forget” approach does not apply. If an organization decides to treat the threat as likely enough to warrant a response, watchTowr points to a fundamental issue: even after a patch is released, installing the update will not make it possible to determine whether unauthorized access was obtained before it was applied. This means that the patch must be combined with containment measures and checks for compromise.
The Citrix guide for suspected NetScaler compromise instructs administrators to:
- Preserve evidence: a snapshot of the VPX instance, logs from remote syslog servers and the NetScaler Console, a technical support bundle, and a packet engine memory dump.
- Isolate the device from the network.
- Change all passwords of service accounts and secrets stored on the device; reset passwords of users who authenticated through it; revoke certificates and private keys.
- Prevent access to the management interface from the internet. Citrix explicitly states: “NetScaler management services should never be exposed to the public internet.”
An additional tool for checks can be the detection scripts from the Dutch National Cyber Security Centre (NCSC-NL), developed after exploitation of a NetScaler vulnerability in 2025. The scripts examine a running device, memory dumps and disk images for signs of compromise. However, the documentation explicitly warns that detection rules are limited, the scripts are not tied to a specific vulnerability and cannot guarantee effectiveness. They should be considered an auxiliary tool, not proof of absence of compromise.
For organizations that have already installed patches for CVE-2026-19490, it is important to bear in mind that the priority of responding to this confirmed vulnerability depends on the configuration: deployments with Gateway or AAA virtual servers that meet the SAML conditions are at the greatest risk, and not all NetScaler instances are equally exposed.
Until an official Citrix advisory appears, every organization with NetScaler on its perimeter must decide, based on its own risk assessment, whether to continue operation with enhanced monitoring, isolate the device, or shut it down completely. If the device remains on the network, the minimum measures are to ensure that the management interface is not accessible from the internet and to prepare a rapid response plan in case Citrix publishes confirming information, which, according to watchTowr, is expected in the week starting 28 September.