INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Citrix NetScaler Zero-Day Exploitation Risk

| 2026-09-27 17:29 CRITICAL HIGH
Executive Summary AI-generated
The Dutch National Cyber Security Centre has issued a pre-notification to organizations in the Netherlands, citing two zero-day vulnerabilities in NetScaler that could allow remote code execution. The flaws are CVE-2026-19490 and CVE-2026-19489, which were disclosed earlier this month but have since been found by Citrix during forensic investigations. These vulnerabilities vary by deployment configuration and enabled features, including issues with denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions. The affected versions include NetScaler ADC and NetScaler Gateway deployments in the 14.1-73.37 and later releases, as well as certain earlier releases such as builds 13.1-63.21 and 14.1-73.32. Organizations are urged to install relevant updates immediately due to active exploitation by attackers.
Technical Mitigations AI-generated
* Implement secure coding practices and input validation mechanisms to prevent improper input validation, which can lead to CVE-2026-88771 vulnerabilities. * Regularly update and patch NetScaler systems with the latest security patches to ensure that known vulnerabilities are addressed before they can be exploited by attackers. * Configure DTLS (Datagram Transport Layer Security) on VPN virtual servers unless an administrator has explicitly disabled it, as this can help prevent memory overflow attacks like CVE-2026-88772. * Monitor for suspicious activity and implement intrusion detection systems to quickly identify and respond to potential security incidents involving unpatched NetScaler appliances.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-88772CVE-2026-88772 CVE-2026-88771CVE-2026-88771 CVE-2026-19490CVE-2026-19490 CVE-2026-19489CVE-2026-19489
Target & Sectors
BENELUX BENELUX
Incident Timeline
‎September 2025
Threat actors exploited two newly discovered vulnerabilities in Citrix's NetScaler products as a zero-day exploit.
‎August 19
Threat actors exploited two newly discovered NetScaler flaws, CVE-2026-19490 and T1588.006, as zero-day vulnerabilities in Citrix's Confirmed version on August 19.
vulnerability CVE-2026-19490
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
‎2026/08/28
Threat actors exploited two newly confirmed vulnerabilities in Citrix NetScaler.
‎September 9
Threat actors exploited the newly confirmed NetScaler flaw, CVE-2026-19490.
vulnerability CVE-2026-19490
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
‎September 15
Threat actors exploited two newly confirmed NetScaler flaws in the 13.1 branch, a vulnerability that reached its End of Maintenance on September 15 under Citrix's release schedule.
general_metric 13.1 later releases
infrastructure 13.1
‎September 26
Threat actors used a zero-day vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances to exploit remote code execution.
tactic Remote Code Execution
organisation NetScaler Gateway
organisation Vulnerability / Network Security
organisation Citrix NetScaler ADC
general_metric 27 Sep
organisation NetScaler RCE
‎September 27, 2026
Threat actors exploited two new NetScaler flaws as zero-day vulnerabilities.
organisation NetScaler
organisation The Dutch National Cyber Security Centre
organisation TCP
organisation DTLS
organisation CVE-2026
infrastructure 14.1-73
infrastructure 13.1-63
infrastructure 9.5
infrastructure 13.1-64
infrastructure 13.1 FIPS
organisation NetScaler ADC
organisation NetScaler Gateway
organisation NetScaler RCE
organisation NetScaler Console
‎Sep 27, 2026
Threat actors exploited two previously unknown vulnerabilities in Citrix NetScaler systems to gain unauthorized access.
‎September 27
Citrix published fixes for the two exploited vulnerabilities on September 27.
‎2026/09/27
Threat actors exploited two newly confirmed NetScaler flaws as zero-day vulnerabilities.
organisation National Cyber Security Center
organisation NetScaler
infrastructure 14.1-73
infrastructure 13.1-63
organisation Two New NetScaler Flaws Exploited
organisation NetScaler ADC
organisation NetScaler Console
organisation VPX
organisation NetScalers
organisation Keep
organisation The NetScaler Management Services
organisation The Hacker News
‎early in the week of September 28
Threat actors exploited two newly discovered vulnerabilities in Citrix's NetScaler products, a remote code execution flaw and another that was also vulnerable to exploitation before patches were available.
tactic Remote Code Execution
organisation UTC
Tactical Metrics
Metrics
infrastructure
‎9.5
Software Version
Metrics
infrastructure
‎14.1-73
Software Version
Metrics
infrastructure
‎13.1-64
Software Version
Metrics
infrastructure
‎13.1-63
Software Version
Metrics
infrastructure
‎13.1
Software Version
Metrics
infrastructure
13
Fips
Intelligence Sources