
🛡️ **CITRIX NetScaler: Two Unpatched RCE Zero-Days Under Active Exploitation**
Published Sunday, September 27, 2026 at 11:53 AM PT BLUF: Citrix has confirmed two remote code execution (RCE) zero-days in NetScaler are actively exploited in ongoing attacks. No patches are available. Organizations running affected NetScaler instances should assume compromise and implement network segmentation immediately. DETAILS: Citrix officially confirmed two separate RCE zero-day flaws in NetScaler products are being exploited in the wild by threat actors. Both vulnerabilities remain unpatched as of publication; Citrix has not released remediation code. Attacks are confirmed active and ongoing—this is not theoretical or in-the-wild proof-of-concept stage. Multiple independent security research outlets (BleepingComputer, The Hacker News, Security Affairs) have independently corroborated the findings. The flaws permit unauthenticated or low-privilege remote code execution on vulnerable NetScaler appliances. IMPACT: ...