Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Citrix admins warned to shut down NetScalers over 2 exploited zero-days

    September 27, 2026

    Cloudflare fixes Containers cross-tenant flaw exposing customer data

    September 27, 2026

    OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex

    September 27, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Citrix admins warned to shut down NetScalers over 2 exploited zero-days
    News

    Citrix admins warned to shut down NetScalers over 2 exploited zero-days

    adminBy adminSeptember 27, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Citrix

    Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week.

    The first signs of the incident appeared when Citrix administrators began reporting on Reddit that IT suppliers and security teams were privately contacting their organizations and advising them to shut down their NetScaler appliances.

    “We got a call from our IT supplier’s security team, they couldn’t give any details but they advised to shut our Netscalers down immediately,” one administrator wrote.

    Other administrators said law enforcement, CERTs, and national cybersecurity agencies had also been contacting organizations about the issue.

    Cybersecurity firm watchTowr later publicly warned that it was “rapidly reacting to rumors” that multiple unpatched Citrix NetScaler remote code execution vulnerabilities were being exploited in the wild after verifying the information with “authoratitive sources.”

    “We are currently rapidly reacting to rumors that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild. While details are scarce, the information is credible,” watchTowr said.

    watchTowr said the warning is not related to CVE-2026-19490 and CVE-2026-19489, two NetScaler flaws disclosed by Citrix in August.

    CVE-2026-19490 is a critical authentication bypass vulnerability affecting NetScaler appliances configured as an AAA virtual server or Gateway under certain configurations.

    As BleepingComputer reported earlier this month, researchers began observing attempts to exploit CVE-2026-19490 after a proof-of-concept exploit became public.

    CISA later added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog on September 9.

    watchTowr later shared more information, saying the current incident involves two remote code execution vulnerabilities that remain unpatched and have already been exploited in the wild.

    “Citrix comms & patches are expected early next week,” watchTowr said.

    “Two vulnerabilities – both RCE. Unpatched, 0days. Exploited in-the-wild – discovered during forensics.”

    BleepingComputer contacted Citrix about the reported zero-days but received no response.

    NCSC warning provides additional details

    The Dutch National Cyber Security Center (NCSC-NL) later shared additional details in a reported pre-notification advisory sent to organizations in the Netherlands.

    Multiple people shared copies of the notification online, which says the agency received information from a European partner CERT regarding two critical zero-day vulnerabilities in Citrix NetScaler.

    According to the notification, each vulnerability can independently lead to remote code execution, with one allowing attackers to place shellcode directly into memory. Technical details about the second vulnerability were still being researched.

    The notice says no CVE identifiers had been assigned and that Citrix had not published an advisory, but was working on patches expected to be released early next week.

    It also states that no indicators of compromise were available at the time and that the NCSC was in contact with Citrix to obtain additional technical information and possible IoCs.

    According to the notification, Citrix discovered the vulnerabilities during an incident response investigation in customer environments.

    Those investigations identified active exploitation, after which Citrix submitted a notification under the European Union’s Cyber Resilience Act.

    The NCSC notification says exploitation has been identified in multiple Citrix customers worldwide, although the agency did not know whether the vulnerabilities were being exploited on a widespread scale.

    It also warned that exploitation attempts could increase after Citrix publishes patches and additional technical details about the vulnerabilities.

    Because updating NetScaler appliances can cause downtime, the NCSC said the pre-notification was meant to give organizations time to prepare and implement safeguards where possible, and to install patches quickly once Citrix releases them.

    BleepingComputer contacted the Dutch NCSC to confirm whether the advisory circulating online was legitimate.

    The agency declined to confirm the notification, but its response mirrors reports from Citrix administrators who said cybersecurity agencies had privately shared information about the vulnerabilities.

    “As part of our role as the National CSIRT and sectoral CSIRT for designated organizations, the NCSC-NL monitors relevant developments and cyber threats affecting the Netherlands 24/7,” the NCSC-NL told BleepingComputer.

    “We provide information and advice to organizations so that they can take appropriate measures. As you’re not part of our constituency, we cannot disclose any further information at this time.”

    Citrix has not officially disclosed the two vulnerabilities, and no publicly available CVE identifiers, affected version information, indicators of compromise, or official mitigation guidance exist for the reported zero-days.

    Until Citrix releases patches or official guidance, administrators should take Internet-exposed NetScaler appliances offline where possible, or restrict access to trusted networks and IP addresses to reduce their risk.

    At a minimum, do not expose NetScaler management interfaces to the Internet, and restrict access to trusted IP addresses.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCloudflare fixes Containers cross-tenant flaw exposing customer data
    admin
    • Website

    Related Posts

    News

    Cloudflare fixes Containers cross-tenant flaw exposing customer data

    September 27, 2026
    News

    OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex

    September 27, 2026
    News

    Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions

    September 27, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    Woman Arrested, Dragged Away After Quietly Speaking About Flock at City Council Meeting

    September 23, 202650 Views

    How fraudsters target credit unions

    May 4, 202644 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    Woman Arrested, Dragged Away After Quietly Speaking About Flock at City Council Meeting

    September 23, 202650 Views

    How fraudsters target credit unions

    May 4, 202644 Views
    Our Picks

    Citrix admins warned to shut down NetScalers over 2 exploited zero-days

    September 27, 2026

    Cloudflare fixes Containers cross-tenant flaw exposing customer data

    September 27, 2026

    OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex

    September 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.