
Security researchers are warning that two previously undisclosed vulnerabilities in Citrix NetScaler are being exploited in active attacks, with no public patch available for the flaws as of September 27, 2026. The reports describe both vulnerabilities as capable of remote code execution, raising concern because NetScaler appliances commonly sit at the edge of enterprise networks.
Security firm Watch Towr said its information came from forensic investigations and indicated that exploitation had already taken place before a fix was publicly available. Independent researcher Kevin Beaumont also said the reported zero-day situation was real and involved active exploitation. Tenable Research separately documented the reports but stressed that important technical details had not yet been made public.
The two vulnerabilities are being reported as separate from the Citrix NetScaler flaws disclosed in August. At the time of publication, there were no publicly assigned CVE identifiers, CVSS scores, detailed affected-version information, public proof-of-concept exploits or confirmed indicators of compromise specifically tied to the newly reported vulnerabilities.
That lack of technical detail leaves defenders with limited information beyond the exploitation warnings. Tenable said public reporting did not yet establish the vulnerable configurations, exact affected builds or the mechanics of the alleged exploit chain. No threat actor has been publicly identified in connection with the two new vulnerabilities.
An alleged pre-notification attributed to the Dutch National Cyber Security Centre, or NCSC-NL, has added to the reports. According to copies circulated online, the document claimed that exploitation had been identified at multiple Citrix customers worldwide and that one of the vulnerabilities involved placing shellcode in memory. The authenticity of that leaked notification has not been independently confirmed, and Tenable said it had not obtained or reviewed the original document.
Reports from administrators in the Citrix community have also described warnings to take NetScaler systems offline. Some users have claimed that Citrix is distributing an early fix privately to customers ahead of a broader public release. Those reports have not been independently verified, and build numbers circulating in community discussions should not be treated as confirmed remediation versions.
Citrix has dealt with several exploited NetScaler flaws this year
The reported zero-days follow a series of NetScaler security incidents in 2026. In August, Citrix disclosed CVE-2026-19490, an authentication-bypass vulnerability with a CVSS v4 score of 9.3, and CVE-2026-19489, a memory-overflow vulnerability rated 8.8. Citrix issued fixes for affected supported releases.
CVE-2026-19490 was later added to CISA’s Known Exploited Vulnerabilities catalog on September 9. Security authorities also reported exploitation attempts against that vulnerability. Tenable said the two newly reported zero-days do not appear to be the same flaws as CVE-2026-19490 or CVE-2026-19489.
Earlier research from watchTowr also showed how serious NetScaler memory-corruption vulnerabilities can become. In August, the firm published technical analysis of CVE-2026-8452 and reported that the vulnerability could be exploited for pre-authentication remote code execution, despite its original classification by Citrix as a memory-overflow issue that could cause unpredictable behavior or denial of service.
That research does not establish that the newly reported September vulnerabilities use the same technique. The only specific technical detail currently circulating about the new flaws is the unverified claim in the alleged NCSC notification concerning shellcode being placed in memory.
NetScaler appliances are commonly used for remote access, application delivery, load balancing and authentication, including services such as VPN, ICA Proxy, CVPN, RDP Proxy and AAA. A vulnerability that allows remote code execution on an internet-facing appliance therefore involves infrastructure positioned directly at a network boundary.
Citrix’s existing guidance for suspected NetScaler compromise calls for preserving evidence before destructive remediation where possible. Its response procedures include collecting technical support bundles, relevant logs and other forensic information, followed by isolation of affected systems and changes to credentials and secrets associated with the appliance and accounts that authenticated through it.
Those procedures were published for suspected compromise generally and are not a vulnerability-specific workaround for the two newly reported zero-days.
The situation is also relevant to organizations still running older NetScaler branches. NetScaler 13.1 reached End of Maintenance on September 15, 2026, although there had not yet been a public Citrix statement establishing how the newly reported vulnerabilities would be handled for that branch.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.



