Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days Under Active Exploitation
Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days (TL-2026-2688) is a critical-severity software vulnerability, first published 2026-09-27. It has no confirmed attribution, affects Cloud Software Group (Citrix) NetScaler ADC, maps to 9 MITRE ATT&CK techniques (T1059, T1071, T1133), and is covered by 9 detection rules and 14 indicators of compromise.
Key facts for TL-2026-2688
- Threat ID
- TL-2026-2688
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-27
- Last reviewed
- 2026-09-27
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, critical infrastructure, finance, health, managed service providers
- Target regions
- netherlands, Europe
- Detection rules
- 9
- Indicators of compromise
- 14
Security firm watchTowr says two distinct, unpatched remote-code-execution vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited in the wild, discovered during forensic investigations of compromised environments. Citrix has issued no bulletin, CVE identifiers, affected-build list, or IOCs as of September 27, 2026; patches are expected early the week of September 28. The claim surfaced amid a viral, less-specific shutdown warning from the X account International Cyber Digest and a Dutch NCSC-NL pre-notification, and is explicitly distinct from the already-patched authentication-bypass CVE-2026-19490/CVE-2026-19489 pair (fixed August 19, 2026; CVE-2026-19490 added to CISA KEV September 9, 2026).
How Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days works
On September 26, 2026, threat-intelligence firm watchTowr disclosed that it had identified two separate, unpatched remote code execution (RCE) vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances, both already being exploited in the wild. watchTowr's account is unusual in its provenance: the firm says it found the flaws while performing forensic investigations for clients, i.e., the exploitation was discovered because organizations had already been compromised, rather than through proactive vulnerability research. As of this writing, Citrix has published no security bulletin, no CVE identifiers, no CVSS score, no confirmed list of affected builds, and no indicators of compromise for either flaw. watchTowr says it expects Citrix communications and a patch early in the week of September 28, 2026.
One of the two vulnerabilities is reported to allow an attacker to inject and run shellcode directly in memory on the appliance, without dropping a file to disk, which defeats file-based antivirus/EDR detection that many organizations rely on for appliance protection. No further technical detail (root cause, CWE class, authentication requirement, or specific affected virtual-server configuration) has been made public for either bug.
Subsequent reporting added technical color while still stopping short of vendor confirmation. One outlet framed the likely exploit chain as memory corruption -- a heap overflow, stack buffer overflow, or use-after-free -- paired with an information leak defeating ASLR/DEP, though this was reporter inference rather than a watchTowr or Citrix technical disclosure. The same reporting described plausible post-exploitation actions consistent with a file-less RCE -- spawning a reverse shell, creating rogue administrator accounts/sessions, or planting a web shell that never touches disk -- and cited Citrix's July 2026 CVE-2026-8452 (an unauthenticated RCE via a SAML-related heap overflow) as a comparable prior flaw class. Defender guidance published alongside these reports recommended watching for unexpected core dumps or service restarts under /var/core/ and /var/nslog/, unauthorized changes to the ns.conf master configuration file, rogue admin accounts or unfamiliar SAML identity-provider configuration, admin sessions from unexpected geographies, and unauthorized outbound connections from NetScaler appliance IP addresses -- offered as forensic hypotheses for a still-technically-undisclosed exploit rather than confirmed IOCs from an observed intrusion.
The disclosure landed inside a chaotic 24-48 hour information environment. A viral, far less specific post from the X account 'International Cyber Digest' claimed an 'unknown critical' NetScaler zero-day had prompted governments and organizations to shut down all NetScaler devices immediately, without technical substantiation. Managed service providers, MDR vendors, and national CERT/CSIRT teams reportedly relayed the same shut-it-down guidance to clients over the same weekend. The Dutch National Cyber Security Centre (NCSC-NL) issued advance/pre-notification guidance and is reported to have raised its advisory NCSC-2026-0318 rating to 'high'; NCSC-NL's early-warning posture is linked by some reporting to the EU Cyber Resilience Act (effective September 11, 2026), which obligates vendors to report actively-exploited vulnerabilities to European authorities while an internal investigation and fix are still in progress. Some reporting raises the possibility that part of the shutdown panic is downstream confusion with the already-known, already-patched CVE-2026-19490/CVE-2026-19489 authentication-bypass pair rather than confirmation of a wholly new bug class -- watchTowr, however, was explicit that the two RCEs it identified are unpatched and distinct from that prior pair.
The broader context matters for prioritization: CVE-2026-19490 (CWE-288, Authentication Bypass Using an Alternate Path or Channel; CVSS 9.3) was disclosed and patched by Citrix on August 19, 2026 (security bulletin CTX696939, alongside CVE-2026-19489), affecting NetScaler ADC/Gateway configured as an AAA virtual server or Gateway service (SSL VPN, ICA Proxy, CVPN, RDP Proxy). CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026, after observing active exploitation, with a Binding Operational Directive 26-04 remediation deadline of September 12, 2026 for U.S. federal civilian agencies, and forensic-triage guidance beyond simple patching. NetScaler 13.1 separately reached End of Maintenance on September 15, 2026, raising the question of whether that branch will receive a fix for the two new, still-unnamed RCEs at all. Citrix's own standing general-compromise guidance (CTX694799) instructs administrators who suspect any NetScaler compromise to preserve a VPX snapshot or forensic image, system time/NTP configuration, a Technical Support Bundle, and local/centralized logs before remediating, and to request Citrix Support's IOC-detection shell script via a Severity 2 ticket; it also reiterates that NetScaler Management Service interfaces should never be exposed to the public internet. Citrix NetScaler ADC/Gateway has a multi-year pattern of pre-authentication, internet-facing RCE and auth-bypass zero-days exploited at scale before patches exist (CitrixBleed CVE-2023-4966; CVE-2025-6543 and CVE-2025-7775/7776/8424 in 2025; CVE-2026-8451/8452/8655/10816/10817/13474 disclosed July 2026; CVE-2026-3055/CVE-2026-4368 exploited from March 2026), which is the backdrop against which defenders and regulators reacted so aggressively to an unconfirmed, undocumented pair of new bugs.
MITRE ATT&CK techniques used in TL-2026-2688
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application
Persistence
T1136.001 Local Account; T1505.003 Web Shell
Credential Access
T1556 Modify Authentication Process
Resource Development
Defense Evasion
Affected products and versions in Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days
- Cloud Software Group (Citrix) — NetScaler ADC
Vulnerable versions: Unconfirmed - Citrix has not published affected builds for the two new RCEs as of 2026-09-27
Fixed in: None yet - patch expected week of 2026-09-28 - Cloud Software Group (Citrix) — NetScaler Gateway
Vulnerable versions: Unconfirmed - Citrix has not published affected builds for the two new RCEs as of 2026-09-27
Fixed in: None yet - patch expected week of 2026-09-28
Remediation for Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days
Patches
- No patch is available for the two new RCEs as of September 27, 2026; Citrix has stated communications and fixes are expected early in the week of September 28, 2026
- The related, distinct, already-patched CVE-2026-19490/CVE-2026-19489 authentication-bypass pair is fixed in NetScaler ADC/Gateway 14.1-73.32 and 13.1-63.21 (and corresponding FIPS/NDcPP builds), per Citrix bulletin CTX696939, August 19, 2026
Immediate actions
- Where no patch or vendor workaround exists, power down or fully isolate internet-facing NetScaler ADC/Gateway appliances, per NCSC-NL and MSP/MDR guidance circulating September 26-27, 2026
- Ensure NetScaler Management Service interfaces are never exposed to the public internet, per Citrix's standing CTX694799 guidance
- Before taking any remediation action, preserve forensic evidence: a VPX snapshot or forensic image, system time/timezone/NTP configuration, a Technical Support Bundle, and local and centralized (syslog/Console) logs, per CTX694799
- Open a Severity 2 Citrix Support ticket to request Citrix's IOC-detection shell script for compromise triage on any appliance suspected of exposure
- Confirm all NetScaler ADC/Gateway instances are already updated past 14.1-73.32 / 13.1-63.21 (or the corresponding FIPS/NDcPP builds) to close the already-known CVE-2026-19490/CVE-2026-19489 authentication bypass, which remains a live risk independent of the new RCEs
Workarounds
- No vendor-published workaround exists for the two new RCEs as of September 27, 2026
- Where continued operation is unavoidable, restrict AAA/Gateway virtual server and Management Service exposure to trusted networks only, and increase log retention/forwarding to support later forensic triage
Longer-term hardening
- Apply Citrix's patch for the two new unpatched RCEs immediately upon release, expected early in the week of September 28, 2026
- Plan migration off the NetScaler 13.1 branch, which reached End of Maintenance on September 15, 2026 and may not receive a fix for the new RCEs
- Monitor Citrix's official security bulletin channel and the CISA KEV catalog for updated advisories, CVE assignment, and affected-build lists
- Review exposure of AAA/Gateway virtual servers (SSL VPN, ICA Proxy, CVPN, RDP Proxy) to the public internet and restrict to only what is operationally required
- Given NetScaler's repeated 2023-2026 history of pre-auth zero-day exploitation, treat internet-facing NetScaler as a standing high-risk asset class requiring continuous monitoring, not a one-time patch target
Timeline of Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days
- Citrix publishes security bulletin CTX696939, disclosing and patching the distinct, unrelated CVE-2026-19490 (authentication bypass, CWE-288, CVSS 9.3) and CVE-2026-19489 in NetScaler ADC/Gateway.
- Active exploitation of CVE-2026-19490 is first reported, ahead of its later addition to the CISA KEV catalog.
- CISA adds CVE-2026-19490 to its Known Exploited Vulnerabilities catalog, triggering Binding Operational Directive 26-04 remediation and forensic-triage requirements for federal civilian agencies.
- The EU Cyber Resilience Act takes effect, obligating Citrix to report actively-exploited vulnerabilities to European authorities while its investigation and fix for the new RCEs are still in progress.
- BOD 26-04 deadline for U.S. federal civilian executive branch agencies to remediate CVE-2026-19490.
- NetScaler 13.1 reaches End of Maintenance, raising uncertainty over whether that branch will receive a fix for the two new unpatched RCEs.
- watchTowr discloses that it identified two separate, unpatched NetScaler ADC/Gateway RCE vulnerabilities during forensic investigations, both already exploited in the wild; NCSC-NL is reported to issue pre-notification guidance and MSP/MDR vendors advise clients to power down appliances.
- X account International Cyber Digest posts a viral, technically unsubstantiated claim that an 'unknown critical' NetScaler zero-day has prompted governments and organizations to shut down devices immediately.
- The Hacker News and other outlets report the two unpatched RCEs; no CVE identifiers, CVSS scores, affected-build lists, or IOCs have been published by Citrix; NCSC-NL's advisory NCSC-2026-0318 is reported raised to a 'high' rating.
- Citrix communications and a patch for the two new RCEs are expected early this week, per watchTowr (forward-looking, not yet confirmed as of research time).
Sources cited for Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
- Citrix CTX694799 - General guidance for suspected NetScaler compromise
- Citrix CTX696939 - Security Bulletin: CVE-2026-19490 / CVE-2026-19489
- CISA Known Exploited Vulnerabilities Catalog - CVE-2026-19490
- Unpatched NetScaler Zero-Days Exploited, watchTowr Says
- Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks
- Citrix NetScaler Zero-Day Emergency: Why Organizations Are Shutting Down Appliances
- ETR: CVE-2026-19490 Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
- AGTP: Citrix NetScaler emergency shutdown orders recap
- International Cyber Digest: viral unverified NetScaler zero-day claim
More in vulnerability
- Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)
- Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation
- Zero-Permission Android Apps Can Chain AtlasService and olc2 to Gain Root on OnePlus/OPPO Devices via OxygenOS Confused-Deputy Flaws
- Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)
- CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud Orchestrator Auth Bypass, F5 BIG-IP APM Heap Overflow
Detection coverage for TL-2026-2688
As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2688 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.