Security1 publisher2 min readPublished
Attackers are exploiting two unpatched NetScaler RCE flaws, watchTowr says
watchTowr says attackers exploited two remote code execution flaws in Citrix NetScaler ADC and Gateway before any fix existed. The August patch for CVE-2026-19490 fixes a different bug, so every operator now has to decide whether to keep the box online and whether to assume it is breached.
The Watch · Security desk

What happened
- Citrix has not confirmed the flaws or said whether appliances on the August builds, 14.1-73.32 and 13.1-63.21, or anything newer are affected.
- watchTowr said the attacks were found during forensic investigations and that Citrix communications and patches are expected early in the week of September 28.
- On r/Citrix, an administrator said their IT supplier had phoned to advise shutting NetScalers down immediately, and others said their organizations had done the same.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Because watchTowr places the exploitation before any fix, installing Citrix's patch when it ships will not show whether an attacker is already inside, so the compromise assessment cannot wait for the patch.
- constraint Without Citrix indicators of compromise or a workaround, a clean result from the Dutch NCSC's generic 2025 check scripts, whose README offers no guarantee of effectiveness, does not clear an appliance.
- exposure Operators still on 13.1 may get no patch at all, since the branch left maintenance 11 days before watchTowr's warning and Citrix has not said it will be fixed.
Everything public so far comes from watchTowr. Its first post on X on September 26 said it was reacting to rumors of several unpatched NetScaler RCE vulnerabilities in the wild [8]. "While details are scarce, the information is credible," it wrote [9]. A follow-up at 22:19 UTC gave the fuller account and directed further questions to Citrix [10]. The firm has worked on this product before. In August it showed that a heap overflow Citrix patched in June could be used for remote code execution [12].
Citrix had published nothing about the new flaws as of Sunday morning, according to The Hacker News, which asked Cloud Software Group, the owner of Citrix and NetScaler, for comment [23]. Where the IT suppliers' shutdown warnings came from is not established [14].
The target is familiar. NetScaler ADC and Gateway sit at the network edge, handling VPN and remote access, load balancing and user authentication [4]. A NetScaler flaw was exploited as a zero-day against Dutch organizations in 2025 [17]. CISA added the August authentication bypass to its Known Exploited Vulnerabilities catalog on September 9 [6]. watchTowr has released no evidence and named no victim, and it has not said whose forensic investigations found the exploitation [11]. On that record there is no basis yet for tying the new attacks to whoever ran the earlier NetScaler intrusions [11].
After the 2025 zero-day, the Netherlands' National Cyber Security Center said updating alone did not remove the risk, because an attacker could keep access gained before the patch [18]. Citrix's existing guidance for a suspected compromise says to preserve evidence first: a snapshot of a VPX instance, the logs held on remote syslog servers and NetScaler Console, a technical support bundle and a core dump of the packet engine [19]. Next comes isolating the appliance. Then every service account password and secret stored on it gets changed, users who signed in through it get password resets, and its certificates and private keys are revoked [20]. "The NetScaler Management Services should never be exposed to the public internet," the guidance says [21].
Citrix's sequence puts evidence collection ahead of the immediate shutdowns administrators described on r/Citrix [19][13].
What to watch
- Citrix's bulletin, which watchTowr expects early in the week of September 28: whether it names affected builds, including 14.1-73.32 and 13.1-63.21, and publishes indicators of compromise.
- Whether Citrix commits to a fix for NetScaler 13.1 after its September 15 End of Maintenance.
- Whether watchTowr or the unnamed investigators publish evidence or victims, or CISA adds the new flaws to its Known Exploited Vulnerabilities catalog.