INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Citrix NetScaler Zero-Day Exploitation Risk
| 2026-09-27 17:29 CRITICAL HIGHExecutive Summary AI-generated
The Dutch National Cyber Security Centre has issued a pre-notification to organizations in the Netherlands, citing two zero-day vulnerabilities in NetScaler that could allow remote code execution. The flaws are CVE-2026-19490 and CVE-2026-19489, which were disclosed earlier this month but have since been found by Citrix during forensic investigations. These vulnerabilities vary by deployment configuration and enabled features, including issues with denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions. The affected versions include NetScaler ADC and NetScaler Gateway deployments in the 14.1-73.37 and later releases, as well as certain earlier releases such as builds 13.1-63.21 and 14.1-73.32. Organizations are urged to install relevant updates immediately due to active exploitation by attackers.
Technical Mitigations AI-generated
* Implement secure coding practices and input validation mechanisms to prevent improper input validation, which can lead to CVE-2026-88771 vulnerabilities.
* Regularly update and patch NetScaler systems with the latest security patches to ensure that known vulnerabilities are addressed before they can be exploited by attackers.
* Configure DTLS (Datagram Transport Layer Security) on VPN virtual servers unless an administrator has explicitly disabled it, as this can help prevent memory overflow attacks like CVE-2026-88772.
* Monitor for suspicious activity and implement intrusion detection systems to quickly identify and respond to potential security incidents involving unpatched NetScaler appliances.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-88772CVE-2026-88772
CVE-2026-88771CVE-2026-88771
CVE-2026-19490CVE-2026-19490
CVE-2026-19489CVE-2026-19489
Target & Sectors
BENELUX
BENELUX
Incident Timeline
September 2025
Threat actors exploited two newly discovered vulnerabilities in Citrix's NetScaler products as a zero-day exploit.
August 19
Threat actors exploited two newly discovered NetScaler flaws, CVE-2026-19490 and T1588.006, as zero-day vulnerabilities in Citrix's Confirmed version on August 19.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-19490
The new flaws are not the authentication bypass,
CVE-2026-19490
, that Citrix
fixed on August 19
and that CISA
added
to its Known Exploited Vulnerabilities catalog on September 9.
attribution
Known Exploited
The new flaws are not the authentication bypass,
CVE-2026-19490
, that Citrix
fixed on August 19
and that CISA
added
to its Known Exploited Vulnerabilities catalog on September 9.
tactic
T1588.006 - Vulnerabilities
The new flaws are not the authentication bypass,
CVE-2026-19490
, that Citrix
fixed on August 19
and that CISA
added
to its Known Exploited Vulnerabilities catalog on September 9.
2026/08/28
Threat actors exploited two newly confirmed vulnerabilities in Citrix NetScaler.
September 9
Threat actors exploited the newly confirmed NetScaler flaw, CVE-2026-19490.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-19490
The new flaws are not the authentication bypass,
CVE-2026-19490
, that Citrix
fixed on August 19
and that CISA
added
to its Known Exploited Vulnerabilities catalog on September 9.
attribution
Known Exploited
The new flaws are not the authentication bypass,
CVE-2026-19490
, that Citrix
fixed on August 19
and that CISA
added
to its Known Exploited Vulnerabilities catalog on September 9.
tactic
T1588.006 - Vulnerabilities
The new flaws are not the authentication bypass,
CVE-2026-19490
, that Citrix
fixed on August 19
and that CISA
added
to its Known Exploited Vulnerabilities catalog on September 9.
September 15
Threat actors exploited two newly confirmed NetScaler flaws in the 13.1 branch, a vulnerability that reached its End of Maintenance on September 15 under Citrix's release schedule.
Click on any entity below to view its context and source!
general_metric
13.1 later releases
The 13.1 branch also deserves attention because that release line reached End of Maintenance on September 15.
NetScaler 13.1 reached End of Maintenance on September 15 under
Citrix's release schedule
, and Citrix has not said whether it will get one.
infrastructure
13.1
The 13.1 branch also deserves attention because that release line reached End of Maintenance on September 15.
NetScaler 13.1 reached End of Maintenance on September 15 under
Citrix's release schedule
, and Citrix has not said whether it will get one.
September 26
Threat actors used a zero-day vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances to exploit remote code execution.
Click on any entity below to view its context and source!
tactic
Remote Code Execution
Swati Khandelwal
Sep 27, 2026
Vulnerability / Network Security
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.
organisation
NetScaler Gateway
Swati Khandelwal
Sep 27, 2026
Vulnerability / Network Security
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.
organisation
Vulnerability / Network Security
Swati Khandelwal
Sep 27, 2026
Vulnerability / Network Security
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.
organisation
Citrix NetScaler ADC
Swati Khandelwal
Sep 27, 2026
Vulnerability / Network Security
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.
general_metric
27 Sep
Swati Khandelwal
Sep 27, 2026
Vulnerability / Network Security
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.
organisation
NetScaler RCE
watchTowr's first
post on X
on September 26 said it was reacting to rumors of several unpatched NetScaler RCE vulnerabilities in the wild.
September 27, 2026
Threat actors exploited two new NetScaler flaws as zero-day vulnerabilities.
Click on any entity below to view its context and source!
organisation
NetScaler
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day
Pierluigi Paganini
September 27, 2026
Citrix confirmed two critical NetScaler zero-days were exploited before patches were available, with attackers able to remotely execute code.
organisation
The Dutch National Cyber Security Centre
The Dutch National Cyber Security Centre also sent a pre-notification to organizations in the Netherlands.
organisation
TCP
These vulnerabilities vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions.”
reads the advisory
.
organisation
DTLS
The second flaw, CVE-2026-88772, is a memory overflow that can lead to remote code execution or denial of service, and it affects appliances with DTLS enabled.
organisation
CVE-2026
The two zero-day issues are not related to NetScaler vulnerabilities CVE-2026-19490 and CVE-2026-19489 that were
disclosed
in August.
infrastructure
14.1-73
The builds 14.1-73.32 and 13.1-63.21, which fixed the previously disclosed authentication-bypass vulnerability
CVE-2026-19490
, are still within the affected range for these new flaws.
Citrix’s fixes are available in NetScaler ADC and Gateway 14.1-73.37 and later, and in the 13.1-64.23 and later releases.
The feature is available in NetScaler Console service and on-premises deployments with Cloud Connect, starting with version 14.1-73.36, and requires the telemetry channel to be enabled.
infrastructure
13.1-63
The builds 14.1-73.32 and 13.1-63.21, which fixed the previously disclosed authentication-bypass vulnerability
CVE-2026-19490
, are still within the affected range for these new flaws.
infrastructure
9.5
“
Citrix confirmed active exploitation of CVE-2026-88771 (CVSS score of 9.5) and CVE-2026-88772 (CVSS score of 9.5) on unpatched systems and urged customers to install the relevant updates as soon as possible.
infrastructure
13.1-64
Citrix’s fixes are available in NetScaler ADC and Gateway 14.1-73.37 and later, and in the 13.1-64.23 and later releases.
infrastructure
13.1 FIPS
Fixes are also available for the 14.1-FIPS, 13.1-FIPS and 13.1-NDcPP branches.
organisation
NetScaler ADC
Citrix confirmed that two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway were exploited before the company released patches.
organisation
NetScaler Gateway
Citrix confirmed that two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway were exploited before the company released patches.
organisation
NetScaler RCE
“We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild.
organisation
NetScaler Console
Citrix is providing generic Indicators of Compromise (IoCs) through NetScaler Console to help customers quickly assess whether their NetScaler deployments may have been compromised.
Sep 27, 2026
Threat actors exploited two previously unknown vulnerabilities in Citrix NetScaler systems to gain unauthorized access.
September 27
Citrix published fixes for the two exploited vulnerabilities on September 27.
2026/09/27
Threat actors exploited two newly confirmed NetScaler flaws as zero-day vulnerabilities.
Click on any entity below to view its context and source!
organisation
National Cyber Security Center
In 2025, after a NetScaler flaw was
exploited as a zero-day
against Dutch organizations, the Netherlands' National Cyber Security Center
said
that updating alone did not remove the risk, because an attacker could keep access gained before the patch, and told administrators to run its check scripts.
organisation
NetScaler
In August it
showed
that a NetScaler heap overflow Citrix had patched in June could be used for remote code execution.
infrastructure
14.1-73
Citrix has not said whether appliances on the August builds, 14.1-73.32 and 13.1-63.21, or any newer builds, are affected by the new flaws.
infrastructure
13.1-63
Citrix has not said whether appliances on the August builds, 14.1-73.32 and 13.1-63.21, or any newer builds, are affected by the new flaws.
organisation
Two New NetScaler Flaws Exploited
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day.
organisation
NetScaler ADC
NetScaler ADC and NetScaler Gateway sit at the edge of enterprise networks, where they handle VPN and remote access, load balancing, and user authentication.
organisation
NetScaler Console
Citrix's existing
guidance
for a suspected NetScaler compromise says to:
Preserve evidence first: a snapshot of a VPX instance, the logs held on remote syslog servers and NetScaler Console, a technical support bundle, and a core dump of the packet engine.
organisation
VPX
Citrix's existing
guidance
for a suspected NetScaler compromise says to:
Preserve evidence first: a snapshot of a VPX instance, the logs held on remote syslog servers and NetScaler Console, a technical support bundle, and a core dump of the packet engine.
organisation
NetScalers
An administrator posting on
r/Citrix
wrote that their IT supplier's security team had phoned to advise shutting their NetScalers down immediately, without giving details.
organisation
Keep
Keep the management interface off the internet.
organisation
The NetScaler Management Services
"The NetScaler Management Services should never be exposed to the public internet," the guidance says.
organisation
The Hacker News
The Hacker News has asked Cloud Software Group, the company that owns Citrix and NetScaler, and watchTowr for comment.
early in the week of September 28
Threat actors exploited two newly discovered vulnerabilities in Citrix's NetScaler products, a remote code execution flaw and another that was also vulnerable to exploitation before patches were available.
Click on any entity below to view its context and source!
tactic
Remote Code Execution
A
follow-up post
at 22:19 UTC gave the fuller account: two vulnerabilities, both remote code execution, both unpatched, exploited before any fix existed, discovered during forensic investigations, and Citrix communications and patches expected early in the week of September 28.
organisation
UTC
A
follow-up post
at 22:19 UTC gave the fuller account: two vulnerabilities, both remote code execution, both unpatched, exploited before any fix existed, discovered during forensic investigations, and Citrix communications and patches expected early in the week of September 28.
Tactical Metrics
Metrics
infrastructure
9.5
Software Version
Click for context!
“
Citrix confirmed active exploitation of CVE-2026-88771 (CVSS score of 9.5) and CVE-2026-88772 (CVSS score of 9.5) on unpatched systems and urged customers to install the relevant updates as soon as possible.
Metrics
infrastructure
14.1-73
Software Version
Citrix’s fixes are available in NetScaler ADC and Gateway 14.1-73.37 and later, and in the 13.1-64.23 and later releases.
The builds 14.1-73.32 and 13.1-63.21, which fixed the previously disclosed authentication-bypass vulnerability
CVE-2026-19490
, are still within the affected range for these new flaws.
The feature is available in NetScaler Console service and on-premises deployments with Cloud Connect, starting with version 14.1-73.36, and requires the telemetry channel to be enabled.
Citrix has not said whether appliances on the August builds, 14.1-73.32 and 13.1-63.21, or any newer builds, are affected by the new flaws.
Metrics
infrastructure
13.1-64
Software Version
Citrix’s fixes are available in NetScaler ADC and Gateway 14.1-73.37 and later, and in the 13.1-64.23 and later releases.
Metrics
infrastructure
13.1-63
Software Version
The builds 14.1-73.32 and 13.1-63.21, which fixed the previously disclosed authentication-bypass vulnerability
CVE-2026-19490
, are still within the affected range for these new flaws.
Citrix has not said whether appliances on the August builds, 14.1-73.32 and 13.1-63.21, or any newer builds, are affected by the new flaws.
Metrics
infrastructure
13.1
Software Version
The 13.1 branch also deserves attention because that release line reached End of Maintenance on September 15.
NetScaler 13.1 reached End of Maintenance on September 15 under
Citrix's release schedule
, and Citrix has not said whether it will get one.
Metrics
infrastructure
13
Fips
Fixes are also available for the 14.1-FIPS, 13.1-FIPS and 13.1-NDcPP branches.
Intelligence Sources
The Hacker News
2026-09-27
Security Affairs
2026-09-27
Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day
Security Affairs
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-28T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
19x
organisation
Identified Entity
The Dutch National Cyber Security Centre
entity
13x
timeline
Temporal Reference
September 27, 2026
date
5x
infrastructure
Software Version
9.5
version
4x
vulnerability
Exploited CVE
CVE-2026-19490
cve
3x
attribution
Attributing Entity
BleepingComputer
authority
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
Contextual Telemetry
Context Block
8 METRICS
target region
Target Country
Netherlands
country
tactic
Cyber Operation Type
Remote Code Execution
tactic
general metric
Exploitation
88,772
exploitation
vulnerability
CVSS Score
10
score
general metric
Gateway
14
gateway
general metric
Later Releases
13
later releases
infrastructure
Fips
13
fips
general metric
Sep
27
sep
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.