Full Report
Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week. [...]
Analysis Summary
# Vulnerability: Critical Unpatched Remote Code Execution Zero-Days in Citrix NetScaler
## CVE Details
- **CVE ID**: Pending (No identifiers assigned as of reporting)
- **CVSS Score**: Estimated 9.0 - 10.0 (**Critical**)
- **CWE**: Unspecified (Likely CWE-94: Improper Control of Generation of Code or CWE-121: Stack-based Buffer Overflow)
## Affected Systems
- **Products**: Citrix NetScaler (formerly Citrix ADC) and NetScaler Gateway.
- **Versions**: Specific versions are currently undisclosed by the vendor; all current versions should be treated as potentially vulnerable.
- **Configurations**: Internet-exposed appliances are at highest risk. One vulnerability specifically impacts memory handling (shellcode injection).
## Vulnerability Description
While official technical documentation is pending, the flaws consist of two distinct Remote Code Execution (RCE) vulnerabilities discovered during forensic investigations.
1. **Vulnerability A**: Allows an attacker to place shellcode directly into the appliance's memory to achieve execution.
2. **Vulnerability B**: A second independent RCE flaw; technical details are currently being researched by European CERTs and the vendor.
These flaws are distinct from the previously disclosed CVE-2026-19490 and CVE-2026-19489.
## Exploitation
- **Status**: **Exploited in the wild**. Identified during incident response investigations at multiple global organizations.
- **Complexity**: Low to Medium (Remote execution capability).
- **Attack Vector**: Network.
- **PoC Availability**: No public PoC available yet, though private exploit code is circulating among threat actors.
## Impact
- **Confidentiality**: **High** (Full system access and data exfiltration potential).
- **Integrity**: **High** (Ability to modify system configuration and intercepted traffic).
- **Availability**: **High** (Total compromise of the appliance).
## Remediation
### Patches
- **No patches are currently available.** Citrix is expected to release official security updates and an advisory early next week (estimated week of September 28, 2026).
### Workarounds
- **Isolate**: Shutdown Internet-exposed NetScaler appliances immediately if they are not mission-critical until patches are released.
- **Access Control**: Restrict access to NetScaler management interfaces and virtual servers to trusted internal IP addresses/VPNs only.
- **Firewalling**: Implement strict geo-blocking or IP-based whitelisting at the edge firewall to minimize the attack surface.
## Detection
- **Indicators of Compromise**: No specific file hashes or C2 IPs have been publicly released by NCSC-NL or Citrix yet.
- **Detection Methods**:
- Monitor for unusual shell activity or unauthorized processes in the NetScaler underlying FreeBSD shell.
- Inspect memory for suspicious shellcode injections.
- Review logs for unexpected reboots or crashes, which may indicate failed exploit attempts.
## References
- BleepingComputer Article: hxxps[://]www.bleepingcomputer[.]com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
- watchTowr Research: hxxps[://]x[.]com/watchtowrcyber/status/2103891689857228803
- NCSC-NL (General): hxxps[://]www.ncsc[.]nl/