Security researchers have raised urgent alarms after discovering that two unpatched zero-day vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances are currently being exploited in the wild. The critical security flaws, which reportedly allow remote code execution, have triggered immediate defensive responses across enterprise networks globally, with some system administrators opting to take their critical infrastructure appliances completely offline rather than wait for official vendor patches and advisories. The alarming development came to light when the security firm watchTowr published alerts regarding the active exploitation of the flaws. NetScaler ADC and NetScaler Gateway devices sit squarely at the vulnerable perimeter of modern enterprise networks, tasked with managing essential perimeter functions such as virtual private network connections, remote access channels, traffic load balancing, and user authentication procedures. Because these appliances occupy such a privileged position on the network boundary, any successful compromise involving remote code execution grants malicious actors a powerful foothold deep inside organizational environments. Read Also: North Korean Threat Actors Expand Supply Chain Attacks to Terraform Registry and Go Modules with Sophisticated Multi-Channel Malware CISA Adds Microsoft SharePoint and MikroTik RouterOS Flaws to Known Exploited Vulnerabilities Catalog The newly surfaced flaws are distinct from previous security issues that have plagued the product line. Specifically, they are separate from the authentication bypass vulnerability tracked as CVE-2026-19490, a critical security flaw that Citrix previously addressed and patched on August 19. That earlier vulnerability subsequently caught the attention of the Cybersecurity and Infrastructure Security Agency, which formally added it to its Known Exploited Vulnerabilities catalog on September 9. However, while a fix has long existed for the August authentication bypass, the nature of these newly discovered remote code execution flaws remains shrouded in uncertainty regarding patch availability and vulnerable version parameters. According to watchTowr, the newly identified flaws are completely unpatched, and forensic evidence suggests that attackers have been actively exploiting them in the wild before any defensive fix or official vendor mitigation ever existed. Citrix has not yet publicly confirmed the existence of these specific flaws, nor has the company published dedicated patches or immediate workarounds. Furthermore, Citrix has not yet clarified whether appliances running the post-patch August builds, such as versions 14.1-73.32 and 13.1-63.21, or any subsequently released builds, remain susceptible to these new remote code execution vectors. The initial public warning emerged via social media on September 26, when watchTowr posted on X to signal that it was actively reacting to circulating rumors concerning several unpatched remote code execution vulnerabilities impacting NetScaler devices in the wild. Acknowledging the sensitivity of the situation, the firm noted that while detailed technical information remained scarce at the time, the intelligence gathered from the field was credible. A comprehensive follow-up post issued later that evening provided a fuller accounting of the situation, confirming the existence of two distinct remote code execution vulnerabilities that were both unpatched and actively leveraged by malicious operators before software vendors could issue corrective updates. In their public communications, the security researchers indicated that these active exploitations were uncovered during ongoing forensic investigations into compromised environments. At the time of the disclosure, watchTowr directed further technical questions and inquiries regarding remediation directly to Citrix, while noting that official communications and expected patches were anticipated early in the week of September 28. Notably, the firm initially published no direct technical evidence, withheld the identities of any targeted victims, and declined to specify which external forensic investigations had successfully identified the active exploitation campaigns. This disclosure follows previous research published by the firm in August, which demonstrated that a NetScaler heap overflow previously patched by Citrix in June could potentially be weaponized to achieve remote code execution. As news of the unpatched vulnerabilities spread across the cybersecurity community, panic and precautionary measures quickly rippled through administrative channels. Reports of emergency shutdown advice began appearing on community forums such as Reddit on the very same day as the initial disclosures. One system administrator posting within the online community shared that their external IT security supplier had telephoned them with an urgent directive to shut down their organization’s NetScaler appliances immediately, though specific technical details regarding the exact nature of the threat were withheld during the call. Other participants in the discussion thread similarly reported that their respective organizations had made the proactive decision to power down their edge appliances to prevent potential compromise. The sudden scramble to pull appliances offline highlights a major operational challenge facing enterprise defenders. The ultimate source of these urgent supplier warnings has not been formally established in every instance, and because Citrix has yet to release a formal security advisory or bulletin, organizations currently lack official vendor workarounds, patches, or concrete indicators of compromise to scan for. Consequently, network administrators managing NetScaler infrastructure have been forced to make difficult risk calculations, weighing whether to keep critical remote access infrastructure online, isolate it from the broader network, power it off entirely, or operate under the hazardous assumption that their devices may already be compromised. A particularly vexing complication for security teams is the timing of the reported attacks. Because the exploitation activity described by researchers occurred prior to the existence of any software fix, merely installing a future patch will not provide operators with definitive assurance regarding whether an attacker managed to infiltrate their network beforehand. This residual risk echoes historical security incidents involving the platform. In 2025, after a NetScaler vulnerability was aggressively exploited as a zero-day against organizations in the Netherlands, the Netherlands National Cyber Security Center explicitly warned that applying standard software updates alone was insufficient to completely eliminate risk. The Dutch agency pointed out that sophisticated threat actors could easily maintain persistent access gained through exploitation prior to the patch cycle, urging administrators to execute dedicated compromise-checking scripts. Citrix maintains existing documentation and guidelines outlining the recommended containment and investigative steps to take if a NetScaler appliance is suspected of having been compromised. Additionally, the compromise-checking scripts released by the Dutch national cybersecurity agency in 2025 offer another avenue for forensic verification, though they come with distinct operational limitations. The documentation accompanying the live-appliance script notes that the utility is designed to scan for known indicators of file-based compromise, is not tied to a single specific vulnerability, and does not carry an absolute guarantee of effectiveness. Furthermore, that specific detection code had not received major updates since late 2025, leaving questions about its efficacy against newer, previously unseen exploitation vectors. Another pressing concern for enterprise environments involves product lifecycle support and version eligibility. Questions immediately arose regarding which specific versions of NetScaler would ultimately receive security patches if and when Citrix addresses the vulnerabilities. Under Citrix’s official firmware release cycle and support schedule, the NetScaler 13.1 branch officially reached its End of Maintenance milestone on September 15. As a result, many organizations running older but still deployed versions find themselves in administrative limbo, uncertain whether legacy firmware branches will receive the necessary security updates to protect against active attacks. As the cybersecurity community awaits official word from the vendor, Cloud Software Group, the parent company that owns Citrix and NetScaler, has not yet issued comprehensive statements or published technical advisories concerning these newly disclosed remote code execution flaws. Security researchers and enterprise IT teams alike continue to monitor the situation closely for incoming patches, official guidance, and indicators of compromise that can help gauge the true scale and scope of the ongoing threat landscape. Post navigation Google Warns of Renewed Mass Exploitation of Oracle PeopleSoft Vulnerability as ShinyHunters Linked to Global Campaign