<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days-omghmifhw" -->

---
title: Citrix admins warned to shut down NetScalers over 2...
description: Two unpatched Citrix NetScaler zero-day remote code execution vulnerabilities are reportedly being actively exploited in the wild, with security agencies, IT...
canonical: https://daily.dev/posts/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days-omghmifhw
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Citrix admins warned to shut down NetScalers over 2 exploited zero-days | daily.dev
og:description: Two unpatched Citrix NetScaler zero-day remote code execution vulnerabilities are reportedly being actively exploited in the wild, with security agencies, IT...
og:url: https://daily.dev/posts/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days-omghmifhw
og:image: https://api.daily.dev/og/posts/omGHmifHw.png
og:image:alt: Citrix admins warned to shut down NetScalers over 2 exploited zero-days
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Citrix admins warned to shut down NetScalers over 2 exploited zero-days

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 5 min read · 0 upvotes · 0 comments

## Summary

Two unpatched Citrix NetScaler zero-day remote code execution vulnerabilities are reportedly being actively exploited in the wild, with security agencies, IT suppliers, and law enforcement privately warning organizations to shut down or restrict access to their appliances ahead of expected patches. WatchTowr confirmed the rumors with authoritative sources, and a leaked Dutch NCSC-NL pre-notification advisory described the flaws as unrelated to the previously disclosed CVE-2026-19490 and CVE-2026-19489. Citrix reportedly discovered the issues during incident response investigations and has not yet published an official advisory or CVEs, with patches expected early the following week. Administrators are urged to take internet-exposed NetScaler appliances offline or restrict access until patches arrive.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days>

## Questions this post answers

### Are there active exploits against Citrix NetScaler right now that don't have a CVE yet?

Yes, two unpatched remote code execution vulnerabilities in Citrix NetScaler are being exploited in the wild and have no public CVE identifiers as of the report. Citrix discovered them during incident response investigations in customer environments and reported active exploitation across multiple customers worldwide. Patches are expected early the following week, with no official advisory, affected versions, or indicators of compromise published yet.

_daily.dev helps admins track fast-moving zero-day disclosures like this before official patches land._

### What should I do with my Citrix NetScaler appliance if there is no patch yet for the new zero-days?

Take internet-exposed NetScaler appliances offline where possible, or restrict access to trusted networks and IP addresses. At minimum, do not expose NetScaler management interfaces to the internet. The Dutch NCSC-NL recommended this pre-notification approach specifically because updating NetScaler can cause downtime, so preparing safeguards ahead of the patch reduces risk during the exposure window.

_security teams weighing downtime against exposure track guidance like this on daily.dev._

### Is the new unpatched Citrix NetScaler RCE the same as CVE-2026-19490?

No, watchTowr confirmed the newly reported unpatched RCE vulnerabilities are unrelated to CVE-2026-19490 and CVE-2026-19489, the NetScaler flaws Citrix disclosed in August. CVE-2026-19490 is a critical authentication bypass affecting AAA virtual server or Gateway configurations, already added to CISA's Known Exploited Vulnerabilities catalog on September 9, while the new pair are separate, unpatched, unassigned RCE flaws.

_daily.dev keeps overlapping CVE disclosures straight for teams patching multiple NetScaler flaws at once._

## Similar posts on daily.dev

- [Citrix NetScaler bug may be multiple flaws in one](https://daily.dev/posts/citrix-netscaler-bug-may-be-multiple-flaws-in-one-kggs3gauu) · The Register · 0 upvotes · 0 comments
- [Critical Citrix NetScaler Flaw Draws CitrixBleed Comparisons as Exploitation Window Narrows](https://daily.dev/posts/critical-citrix-netscaler-flaw-draws-citrixbleed-comparisons-as-exploitation-window-narrows-iikwjwkhl) · IT Security Guru · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days-omghmifhw)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Citrix admins warned to shut down NetScalers over 2 exploited zero-days","url":"https://daily.dev/posts/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days-omghmifhw","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days-omghmifhw"},"datePublished":"2026-09-27T16:03:30.454Z","dateModified":"2026-09-28T16:51:49.346Z","description":"Two unpatched Citrix NetScaler zero-day remote code execution vulnerabilities are reportedly being actively exploited in the wild, with security agencies, IT...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4d3295ee2536198faf30afbadbe51442?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4d3295ee2536198faf30afbadbe51442?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days-omghmifhw","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,zero-day","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Citrix admins warned to shut down NetScalers over 2 exploited zero-days"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days-omghmifhw#faq","mainEntity":[{"@type":"Question","name":"Are there active exploits against Citrix NetScaler right now that don't have a CVE yet?","acceptedAnswer":{"@type":"Answer","text":"Yes, two unpatched remote code execution vulnerabilities in Citrix NetScaler are being exploited in the wild and have no public CVE identifiers as of the report. Citrix discovered them during incident response investigations in customer environments and reported active exploitation across multiple customers worldwide. Patches are expected early the following week, with no official advisory, affected versions, or indicators of compromise published yet. daily.dev helps admins track fast-moving zero-day disclosures like this before official patches land."}},{"@type":"Question","name":"What should I do with my Citrix NetScaler appliance if there is no patch yet for the new zero-days?","acceptedAnswer":{"@type":"Answer","text":"Take internet-exposed NetScaler appliances offline where possible, or restrict access to trusted networks and IP addresses. At minimum, do not expose NetScaler management interfaces to the internet. The Dutch NCSC-NL recommended this pre-notification approach specifically because updating NetScaler can cause downtime, so preparing safeguards ahead of the patch reduces risk during the exposure window. security teams weighing downtime against exposure track guidance like this on daily.dev."}},{"@type":"Question","name":"Is the new unpatched Citrix NetScaler RCE the same as CVE-2026-19490?","acceptedAnswer":{"@type":"Answer","text":"No, watchTowr confirmed the newly reported unpatched RCE vulnerabilities are unrelated to CVE-2026-19490 and CVE-2026-19489, the NetScaler flaws Citrix disclosed in August. CVE-2026-19490 is a critical authentication bypass affecting AAA virtual server or Gateway configurations, already added to CISA's Known Exploited Vulnerabilities catalog on September 9, while the new pair are separate, unpatched, unassigned RCE flaws. daily.dev keeps overlapping CVE disclosures straight for teams patching multiple NetScaler flaws at once."}}]}
```

