On September 25, a post landed in r/Citrix with the tone of an emergency change. Shut the NetScalers down. People in that thread said the tip had come from the Dutch National Cyber Security Centre as a TLP:AMBER+STRICT pre-notification that was never meant to hit a public forum. Citrix had published nothing. Your appliances were still terminating sessions. That is the cybersecurity story this week: operators acting on a leak because the vendor still hadn’t found the send button.
The leak beat Citrix to your change window
By September 26, researchers at watchTowr were confirming what operators already feared. Two unpatched remote code execution flaws in Citrix NetScaler ADC and NetScaler Gateway, already used in the wild. Kevin Beaumont put it in language your on-call channel understands: the thing is real, attacks are happening, and if you’re sensitive to these bugs you switch the appliance off. As of September 27, Citrix still hadn’t confirmed the flaws and still hadn’t published a fix. Administrators in public threads said they’d already taken boxes offline.

Restricted government intel reached a public subreddit before the vendor reached paying customers. Tenable’s researchers said they hadn’t independently obtained the NCSC-NL notice. You shouldn’t need a third party to launder a leak into something your CAB will believe. When the first trustworthy sentence about a live RCE lives on Reddit, your emergency window belongs to whoever posted, not to whoever will someday assign CVE numbers. Public reporting still says Citrix hopes to ship patches early in the week of September 28. That is a rumor with a calendar, not a control you can deploy tonight.
Your cybersecurity plan assumed a bulletin would arrive
NetScaler operators have earned the reflex to treat vendor silence as a countdown. Tenable counted 13 NetScaler-related entries in CISA’s Known Exploited Vulnerabilities catalog as of September 27, and 24 listings across Citrix products. About two-thirds of tracked actor activity against this family over seven years involved APT groups. The remaining third involved ransomware crews and their affiliates. Code execution on the appliance that terminates SSL and brokers VPN sessions is how those actors like to open a month. You already know the sequel: persistence on the box, theft of session material, and a quiet path around every control you placed behind it.
Reports say these two bugs are unrelated to CVE-2026-19490 and CVE-2026-19489, which already have patches, including one KEV-listed as recently as September 9. File that under ticket hygiene. Your internet-facing ADC still interprets requests before an internal firewall ever classifies them as east-west traffic. Brute-force lockouts on the VPN logon page will keep firing and looking useful. An RCE that never logs in will not. If your threat-protection stack needs a CVE, a plugin, and a content update, it’s late to a fight that started in a restricted inbox in the Netherlands.
Pull the path, then hunt what already walked it
This is a production call wearing a vulnerability costume. If staff, contractors, or partners reach you through NetScaler, you need a fail-closed move that doesn’t wait for a PDF from the manufacturer.
Do this now, in order:
- Build a one-page inventory of every NetScaler ADC and Gateway: internet VIPs, partner circuits, management IPs, firmware build, and the applications behind each virtual server.
- If you cannot live with remote code execution on that path, disable the virtual servers or allowlist source networks down to known corporate egress. Tell the business this is emergency isolation. A dark gateway is an outage. A live, exploited gateway is an incident you haven’t opened yet.
- Snapshot running config, appliance logs, and a support bundle before you reboot. There are still no public indicators of compromise. Your later incident response will run on timestamps and files that look new.
- Unpin the management GUI and API from the internet. Management traffic belongs on a jump host. That security hardening should already have been true last year.
- Rotate anything the appliance touched: VPN users, AAA bindings, LDAP bind accounts, and certificates if you think sessions were stolen.
Keep a tested remote-access bypass that doesn’t depend on this product family. Rehearse a 72-hour stretch where the vendor says nothing and a restricted note shows up in a forum. Defense in depth on an ADC means you can refuse the connection on purpose. A pile of overlapping threat detection tools watching the same VIP is not a kill switch.
Monday is a hunt, not a close-out
When a patch lands, install it. Then leave the case open. No public proof-of-concept doesn’t mean no private one. No published indicators means your SIEM will not auto-close this for you. Look for new files in the appliance shell, unexpected boot tasks, unknown web resources, outbound connections from the ADC you didn’t design, and authentication oddities behind the gateway after the Dutch note started circulating. If you already unplugged, don’t plug back in on a blog post. Rebuild from known-good firmware where you can, restore config from a pre-incident copy, and watch the first hours of traffic the way you would after a suspected web compromise.

Cyber security on an edge ADC is unglamorous: an inventory, a kill switch, and a rebuild drill you can run without waiting for the company logo to appear on an advisory. The restricted note did you a rude favor. It told you the patch calendar was fiction before the CVE numbers existed. If your remote-access path is still live on a product family with this KEV history, you’re not waiting for confirmation. You’re betting the leak was loud and the attackers were slow.
Sources
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
- Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
