Citrix confirms two NetScaler RCE zero-days exploited in attacks

Source: BleepingComputer

Author: Lawrence Abrams

URL: https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/

ONE SENTENCE SUMMARY:

Two unpatched Citrix NetScaler RCE zero-days are reportedly exploited worldwide, prompting private agency warnings, shutdown advice, and imminent patch releases.

MAIN POINTS:

  1. Unpatched Citrix NetScaler zero-days are reportedly exploited in active attacks.
  2. IT suppliers privately urged some organizations to shut down NetScaler appliances immediately.
  3. Law enforcement, CERTs, and national agencies reportedly contacted targets about the threat.
  4. watchTowr corroborated credible reports of multiple in-the-wild NetScaler RCEs.
  5. The incident is explicitly unrelated to August-disclosed CVE-2026-19490 and CVE-2026-19489.
  6. CVE-2026-19490 is an auth bypass already exploited after a public PoC emerged.
  7. CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog September 9.
  8. NCSC-NL described two critical zero-days, each independently enabling remote code execution.
  9. One vulnerability reportedly allows placing shellcode directly into memory.
  10. No CVEs, advisories, affected versions, IoCs, or mitigations are publicly available yet.

TAKEAWAYS:

  1. Expect exploitation to intensify once Citrix publishes patches and technical details.
  2. Prepare now for potential downtime to patch quickly when releases arrive next week.
  3. Reduce exposure by taking Internet-facing NetScaler systems offline where feasible.
  4. Restrict access to trusted networks/IPs, especially for management interfaces.
  5. Monitor for vendor and national CSIRT updates since official IoCs are currently unavailable.