Citrix NetScaler Hit by Two Unpatched RCE Zero-Days Under Active Exploitation
Citrix confirmed on September 27, 2026 that two critical remote code execution (RCE) vulnerabilities affecting NetScaler ADC and NetScaler Gateway are being actively exploited in the wild. Citrix released patches for both flaws, along with six other vulnerabilities disclosed in the same bulletin. According to the report, one of the two actively exploited issues affects every deployment running an affected version, including those in default configuration — meaning no special setup is required to be at risk. The bulletin reportedly followed disclosure activity from security firm watchTowr a day earlier.
Why It Matters
NetScaler ADC and Gateway appliances are widely deployed as internet-facing load balancers and remote access gateways, making them a high-value target for initial access. RCE flaws in these appliances have historically been mass-exploited shortly after disclosure (as seen with prior NetScaler CVEs), and active exploitation prior to or alongside patch release significantly compresses the window defenders have to respond. Any organization running NetScaler ADC or Gateway on an affected version should treat this as urgent, particularly given that one flaw reportedly impacts all default configurations.
What Defenders Should Do Now
- Identify all NetScaler ADC and NetScaler Gateway instances in your environment and confirm current firmware versions against Citrix's advisory.
- Apply Citrix's released patches as a priority — do not wait for a routine maintenance window given confirmed active exploitation.
- Review NetScaler management and gateway access logs for anomalous authentication, unexpected process execution, or unfamiliar files written to the appliance filesystem.
- Hunt for indicators of post-exploitation activity such as webshells, unexpected outbound connections from the appliance, or configuration changes not tied to known administrative activity.
- If patching cannot happen immediately, consider restricting management-plane and gateway exposure, and review any available Citrix mitigation guidance in the advisory.
Developing Story
Details on the specific CVE identifiers, exploitation techniques, and full technical scope are still emerging. This post will be updated as more information becomes available. For the original report, see The Hacker News.