Source: BleepingComputer
Author: Lawrence Abrams
URL: https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
ONE SENTENCE SUMMARY:
Two unpatched Citrix NetScaler RCE zero-days are reportedly exploited worldwide, prompting private agency warnings, shutdown advice, and imminent patch releases.
MAIN POINTS:
- Unpatched Citrix NetScaler zero-days are reportedly exploited in active attacks.
- IT suppliers privately urged some organizations to shut down NetScaler appliances immediately.
- Law enforcement, CERTs, and national agencies reportedly contacted targets about the threat.
- watchTowr corroborated credible reports of multiple in-the-wild NetScaler RCEs.
- The incident is explicitly unrelated to August-disclosed CVE-2026-19490 and CVE-2026-19489.
- CVE-2026-19490 is an auth bypass already exploited after a public PoC emerged.
- CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog September 9.
- NCSC-NL described two critical zero-days, each independently enabling remote code execution.
- One vulnerability reportedly allows placing shellcode directly into memory.
- No CVEs, advisories, affected versions, IoCs, or mitigations are publicly available yet.
TAKEAWAYS:
- Expect exploitation to intensify once Citrix publishes patches and technical details.
- Prepare now for potential downtime to patch quickly when releases arrive next week.
- Reduce exposure by taking Internet-facing NetScaler systems offline where feasible.
- Restrict access to trusted networks/IPs, especially for management interfaces.
- Monitor for vendor and national CSIRT updates since official IoCs are currently unavailable.