Two unpatched NetScaler flaws are reportedly being used in real attacks. There's no CVE number, no Citrix advisory, and no patch. Here's what's solid and what's still a rumor.
What's being reported
Security researchers say two unpatched Citrix NetScaler vulnerabilities capable of remote code execution are being exploited in the wild right now. No CVE identifiers exist yet, Citrix hasn't published a security bulletin, and there's no patch to apply [1]. That combination — credible researcher warnings with almost nothing officially confirmed — is exactly why some administrators have already pulled their NetScaler appliances offline rather than wait.
This is a developing story. What follows separates what independent researchers have actually stated from what originated as an unverified leak.
How this surfaced
The first public trace appeared on September 25, 2026, in a Reddit post on r/Citrix advising people to shut down their NetScaler appliances. The poster attributed the tip to a pre-notification allegedly issued by the Dutch national cyber security center, NCSC-NL, distributed under Traffic Light Protocol AMBER+STRICT handling restrictions — meaning it was never meant to circulate publicly [1]. Tenable's research team has said plainly that it has not independently obtained or reviewed that notification, so its contents remain unverified at the source level, even though the broader claim of exploitation has since been echoed by named researchers.
On September 26, that broader claim got independent backing. Security firm watchTowr posted on X confirming it was aware of the situation and had flagged customer exposure through its platform, while directing further technical questions to Citrix rather than answering them itself [2]. Separately, researcher Kevin Beaumont posted on Mastodon that the situation was real and involved active attacks, advising organizations sensitive to NetScaler risk to consider powering appliances down until a fix exists [3]. Neither post included exploitation mechanics, affected versions, or indicators of compromise.
What is and isn't confirmed
It's worth being precise here, because "zero-day" stories tend to get flattened into a single scary headline. Separating the pieces:
| Item | Status as of Sept 27, 2026 |
|---|---|
| CVE identifier | Not assigned |
| Citrix security advisory | Not published |
| Patch / fixed build | Not available; expected week of Sept 28 per public reporting |
| Public proof-of-concept | None known |
| Indicators of compromise | None publicly released |
| Researcher claim of exploitation | Stated by watchTowr and Kevin Beaumont, without technical detail |
| Scale of exploitation | Not established in public reporting |
Source: Tenable Research Special Operations FAQ, updated September 27, 2026 [1].
None of this means the reports are wrong. watchTowr and Kevin Beaumont are both established names in vulnerability research, and neither has a history of crying wolf on NetScaler. But "two named researchers say exploitation is occurring" is a different evidentiary category than "Citrix confirmed active exploitation in an advisory," and this article keeps that distinction rather than collapsing it.
Not the same bug as August's NetScaler flaws
It's easy to confuse this with Citrix's most recent NetScaler advisory. On August 19, 2026, Citrix published bulletin CTX696939 covering two separate, already-patched issues: CVE-2026-19490, a critical authentication-bypass flaw affecting Gateway and AAA virtual server configurations, and CVE-2026-19489, a lower-severity memory-overflow issue tied to SIP ALG configurations on Large Scale NAT groups. CVE-2026-19490 was added to CISA's Known Exploited Vulnerabilities catalog on September 9, 2026, after independent telemetry showed exploitation attempts [1].
Tenable's researchers state directly that the newly reported zero-days are unrelated to either of those CVEs [1]. If your organization already patched against CVE-2026-19490 and CVE-2026-19489, that work still matters, but it does not address whatever is being described in this new round of reports.
Why the history here raises the stakes
NetScaler's track record is part of why researchers are being taken seriously without a CVE in hand. According to Tenable, as of September 27, 2026, there were 13 NetScaler-related entries in CISA's KEV catalog and 24 for Citrix products overall, stretching back to CVE-2019-19781 [1]. Tenable's own analysis attributes roughly two-thirds of historical NetScaler exploitation activity to advanced persistent threat groups, with the remainder tied to ransomware actors and their affiliates. NetScaler sits at the network edge, handling VPN and remote-access traffic — a role that makes it a durable target regardless of which specific bug is in play this week.
Should you take your NetScaler offline?
There's no universal answer, and this article won't pretend there is one. Some MSPs and MDR providers reportedly told clients to shut appliances down over the weekend rather than wait for Citrix's fix [1]. That's a defensible call for organizations with low risk tolerance, sensitive data behind the appliance, or prior NetScaler compromise history. It's also disruptive — NetScaler often carries VPN, authentication, and application-delivery traffic, so pulling it offline has real operational cost.
A middle path that doesn't require guessing at unconfirmed exploitation details: tighten what's exposed to the internet, restrict management-plane access to trusted networks only, and make sure logging is actually capturing authentication and admin activity right now, before an advisory tells you what to look for retroactively.
What's still unknown
As of this writing, the following remain unconfirmed: the exact vulnerability class or classes involved, which NetScaler builds or configurations are affected, whether one or both flaws require authentication, the scale or geographic spread of exploitation, and whether any specific threat actor or group has been linked to the activity. Readers should treat any post claiming these specifics before an official Citrix advisory with real skepticism.
Bottom line
Right now this is a credible warning from named researchers layered on top of an unverified leak — not a confirmed, vendor-acknowledged incident. That distinction matters for how urgently you act and how much you trust any secondhand technical detail circulating this week. Track Citrix's official channel for the advisory and CVE assignment, and treat anything claiming exploitation mechanics or indicators before that point as unconfirmed.
Sources & References
- Tenable Research Special Operations — "Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities" (updated Sept 27, 2026)
- watchTowr (@watchtowrcyber) on X — Sept 26, 2026 confirmation post
- Kevin Beaumont (@GossiTheDog) on Mastodon — Sept 26, 2026 confirmation post
- Reddit r/Citrix — "Netscaler leak?" — original Sept 25, 2026 report citing an alleged NCSC-NL pre-notification (unverified at the source)
- Tenable CVE database — CVE-2026-19490 (background: unrelated prior NetScaler authentication-bypass flaw)

Technical Discussion & Feedback
Leave a Comment (Authenticated Users)