Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Citrix NetScaler Zero-Days Reportedly Exploited

Two unpatched zero-day vulnerabilities in Citrix NetScaler appliances are reportedly being exploited in attacks. Cybersecurity agencies, researchers and IT providers have privately warned organizations, ahead of patches Citrix is expected to release early next week.

The first reports emerged when administrators said on Reddit that IT suppliers and security teams had advised them to shut down their NetScaler appliances. Security firm watchTowr later said it was responding to credible reports of multiple unpatched remote code execution (RCE) flaws being exploited in the wild. It said the incident was unrelated to CVE-2026-19490 and CVE-2026-19489, vulnerabilities Citrix disclosed in August.

A reported pre-notification from the Dutch National Cyber Security Center (NCSC-NL) said each of the two new vulnerabilities could independently enable RCE. One could let attackers place shellcode directly in memory; technical details about the second were still under investigation. The notice said no CVE identifiers had been assigned and Citrix had not published an advisory.

According to the notice, Citrix found the flaws during incident response investigations in customer environments, which identified active exploitation at multiple customers worldwide. The NCSC-NL declined to confirm the circulating notification to BleepingComputer. The agency said it could not disclose further information to the outlet because it was outside its constituency. Citrix had not responded to BleepingComputer’s request for comment.

No official disclosure, affected-version information, indicators of compromise or mitigation guidance for the reported flaws was publicly available in the article.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.