Security researchers are warning that two unpatched flaws in Citrix NetScaler ADC and NetScaler Gateway appliances allow remote code execution (RCE) and are already being exploited — even though the vendor has published no advisory, no CVE identifiers and no indicators of compromise.

The alarm came from threat-intelligence firm watchTowr, which said on 26 September that it was "rapidly reacting to rumours that multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild", calling the information credible and notifying its clients about their exposure. The company later narrowed the report to two separate code-execution vulnerabilities described as "unpatched, 0days, exploited in the wild — discovered during forensics". British researcher Kevin Beaumont, who closely tracks flaws in edge devices, said he had checked and confirmed it: "Vuln is real though."

As of 27 September, CISA in the US, the UK and Dutch NCSCs and Germany's BSI had published nothing, and Citrix had neither confirmed nor denied the reports. Sources quoted by heise expect an official statement and patches early in the week. watchTowr founder Benjamin Harris advised organisations to take affected appliances offline; Beaumont said government agencies had made the same recommendation, while Citrix does not currently advise a shutdown.

Because NetScaler boxes sit on the network edge and terminate VPN, authentication and application-delivery traffic, a genuine RCE there is a high-value target for both criminals and state actors. Some organisations have reportedly already pulled internet-exposed appliances out of service — disruptive, but sometimes the safer option when no patch or workaround exists.

The episode caps a rough year for the platform. Citrix patched critical flaws in July and again in August, including an authentication bypass tracked as CVE-2026-19490 with a CVSS score of 9.3, which CISA added to its Known Exploited Vulnerabilities catalogue on 9 September. Administrators are advised to inventory every NetScaler instance, confirm exact builds and exposure, restrict management access, preserve logs and forensic images before wiping anything, and monitor Citrix's security bulletin channel rather than social media for the fix.