Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Executive Summary

Citrix confirmed on September 27 that two critical remote code execution vulnerabilities in NetScaler ADC and NetScaler Gateway were actively exploited in the wild. Both flaws affect all deployments of the affected versions, including default configurations. Citrix released patches for the two vulnerabilities and six additional flaws, highlighting the urgency of applying updates to mitigate exploitation.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-27T07:47:57+00:00 - Category: threat-intel

Original Description: Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six other flaws. One of the two affects every deployment on an affected version, including those in the default configuration. The bulletin came a day after security firm watchTowr

"It is difficult to achieve a spirit of genuine cooperation as long as people remain indifferent to the feelings and happiness of others."

— Dalai Lama
Source: The Hacker News