Published Sunday, September 27, 2026 at 11:52 AM PT

BLUF: Two unpatched remote code execution zero-day vulnerabilities in Citrix NetScaler are actively exploited in the wild with no patches available. Any organization operating NetScaler appliances is at immediate risk. Inventory deployments now and implement network isolation where possible pending patch release.

DETAILS

  • Two high-severity RCE vulnerabilities confirmed by Citrix โ€” both capable of remote code execution; CVE identifiers not yet specified in available reporting.
  • Active exploitation confirmed โ€” multiple independent security sources (BleepingComputer, SecurityAffairs, The Hacker News, Tenable) report ongoing attacks in the wild; no patch release date announced as of this alert.
  • No mitigation patches available โ€” Citrix has not released fixes; timeline for patches is unconfirmed.
  • CISA directive to government agencies โ€” Cybersecurity and Infrastructure Security Agency has urged federal agencies to immediately patch/defend; implies critical infrastructure targeting.
  • Initial attack surface unknown but broad โ€” reporting does not specify whether exploitation requires authenticated access or is unauthenticated; scope of affected NetScaler versions not detailed in available summaries.

IMPACT

  • All NetScaler operators are potential targets โ€” scope includes private sector, government, and critical infrastructure.
  • Complete system compromise possible โ€” remote code execution allows attackers to execute arbitrary commands with NetScaler process privileges; potential for lateral movement into protected networks behind the appliance.
  • Active threat environment โ€” exploitation is occurring now, not theoretical; attackers are actively leveraging these flaws against live deployments.

RECOMMENDED ACTIONS

  1. Immediate inventory โ€” identify all Citrix NetScaler instances, versions, and network roles in your environment.
  2. Network isolation โ€” segment NetScaler appliances from sensitive systems if operationally feasible; restrict inbound access to only required administrative users/networks.
  3. Increase monitoring โ€” enable debug/verbose logging on NetScaler; alert on unexpected code execution, shell spawning, or lateral movement originating from the appliance.
  4. Monitor Citrix security advisories hourly โ€” patch release is imminent given CISA involvement; be ready to deploy within hours of availability.
  5. Prepare alternate access paths โ€” if NetScaler is your primary remote access point, identify and test backups in case appliance must be isolated/rebuilt.

SOURCES

Tenable Blog; Citrix Security Advisory; BleepingComputer; SecurityAffairs; The Hacker News; SecurityWeek; CISA public guidance.


Recent high-severity events at publish time:

Recent high-severity events