Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070
6-minute read Sep 27 2026

Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities

Dark blog header image with white hexagon pattern on the right. Orange text reads "Citrix NetScaler Zero-Days" followed by "Frequently Asked Questions" and "September 2026" in white. Tenable Research Special Operations logo in upper center.

There are reportedly two unpatched zero-day Citrix NetScaler vulnerabilities capable of enabling remote code execution that have been actively exploited in the wild, with no patches available at this time.

Key takeaways

  1. Reports indicate that there are two critical zero-day vulnerabilities in Citrix NetScaler.
  2. The reports originate from a pre-notification sent out ahead of public disclosure, so there are currently no specific details about these flaws and no patches available.
  3. This post will be updated as new information becomes available.

Background

Tenable's Research Special Operations (RSO) team has compiled this blog to answer Frequently Asked Questions (FAQ) regarding two reported zero-day vulnerabilities in Citrix NetScaler that sources say were actively exploited in the wild. The following FAQ is based on limited public information. This post will be updated with additional details once more information becomes public over the next week.

FAQ

What is the source of the NetScaler vulnerabilities?

On September 25, 2026, reports surfaced through a reddit post on r/Citrix regarding advice to shut down “Netscalers.” This included a report from a user that said this information came from the “Dutch national cyber security center” and further details included a note about two zero-day vulnerabilities.

On September 26, 2026, additional reports confirming the existence of these flaws became public, including social posts from researchers at watchTowr on X, as well as Kevin Beaumont on Mastodon.

What is the context surrounding the National Cyber Security Centre (NCSC-NL) alert?

The Reddit post on r/Citrix cited details from an NCSC-NL pre-notification that had not yet been made public. Community members in that thread said the pre-notification was distributed under Traffic Light Protocol (TLP):AMBER+STRICT restrictions. Tenable's RSO has not independently obtained or reviewed the contents of this notification.

Has Citrix confirmed the presence of zero-day vulnerabilities?

As of September 27, a formal security advisory from Citrix has not been published.

What are these zero-day vulnerabilities?

Based on public reporting as of September 27, there are reportedly two zero-day vulnerabilities in Citrix NetScaler devices that can lead to remote code execution (RCE):

CVEDescriptionCVSSv3
Not AssignedCitrix NetScaler RCEN/A
Not AssignedCitrix NetScaler RCEN/A

watchTowr confirmed details for both on September 26, 2026:

 

 

Are these zero-day vulnerabilities related to CVE-2026-19490 and CVE-2026-19489?

No. Neither CVE-2026-19490 nor CVE-2026-19489 appears to be related. Both are previously disclosed vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway for which patches are available. CVE-2026-19490 was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026.

Reports say these vulnerabilities were exploited. How widespread are the attacks?

Based on public reporting, it has not been determined whether exploitation has reached widespread scale. On September 26, Kevin Beaumont stated: “The Netscaler zero day thing is real, being used in active attacks. No patch yet, if sensitive to Netscaler vulns switch it off.”

How many Citrix NetScaler vulnerabilities have been exploited in the wild in the past?

Citrix NetScaler devices have historically been a popular target for attackers. Including CVE-2026-19490, as of September 27, 2026, there were 13 NetScaler-related entries in CISA's KEV catalog and 24 entries for Citrix products overall. The RSO team has covered several notable incidents:

CVEDescriptionKEV addedRansomwareTenable blogs
CVE-2026-8452Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow vulnerability2026-08-26Unknown-
CVE-2026-3055Citrix NetScaler Out-of-Bounds Read vulnerability2026-03-30Unknown-
CVE-2025-7775Citrix NetScaler Memory Overflow vulnerability2025-08-26UnknownCVE-2025-7775: Citrix NetScaler ADC and NetScaler Gateway Zero-Day Remote Code Execution Vulnerability Exploited in the Wild
CVE-2025-5777Citrix NetScaler ADC and Gateway Out-of-Bounds Read vulnerability (“CitrixBleed 2”)2025-07-10KnownCVE-2025-5777, CVE-2025-6543: Frequently Asked Questions About CitrixBleed 2 and Citrix NetScaler Exploitation
CVE-2025-6543Citrix NetScaler ADC and Gateway Buffer Overflow vulnerability2025-06-30UnknownCVE-2025-5777, CVE-2025-6543: Frequently Asked Questions About CitrixBleed 2 and Citrix NetScaler Exploitation
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow vulnerability2024-01-17UnknownCVE-2023-6548, CVE-2023-6549: Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC and NetScaler Gateway
CVE-2023-6548Citrix NetScaler ADC and NetScaler Gateway Code Injection vulnerability2024-01-17UnknownCVE-2023-6548, CVE-2023-6549: Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC and NetScaler Gateway
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow vulnerability (“CitrixBleed”)2023-10-18Known[1] [2] [3]
CVE-2023-3519Citrix NetScaler ADC and NetScaler Gateway Code Injection vulnerability2023-07-19KnownCVE-2023-3519: Critical RCE in Netscaler ADC (Citrix ADC) and Netscaler Gateway (Citrix Gateway)
CVE-2020-8193Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass vulnerability2021-11-03UnknownGovernment Agencies Warn of State-Sponsored Actors Exploiting Publicly Known Vulnerabilities
CVE-2019-19781Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution vulnerability2021-11-03Known[1] [2]

Which threat actors are exploiting these vulnerabilities?

No details about threat actors have been made public at this time. However, based on our research, roughly two-thirds of threat actor activity targeting Citrix NetScaler over the last seven years involved advanced persistent threat (APT) groups, while one-third involved ransomware groups and their affiliates.

Is there a proof-of-concept (PoC) available for these vulnerabilities?

As of September 27, 2026, there are no public proofs-of-concept (PoCs) for these vulnerabilities.

Are patches or mitigations available?

As of September 27, a formal security advisory from Citrix has not been published as of this writing and no patches are currently available. However, public reporting indicates that Citrix plans to release patches early in the week of September 28, 2026.

Are there any indicators of compromise for these vulnerabilities?

There are currently no indicators of compromise (IoCs) publicly available.

Has Tenable Research classified these vulnerabilities as part of Vulnerability Watch?

No. Tenable Research will classify the reported Citrix NetScaler zero-day vulnerabilities as part of Vulnerability Watch once CVE IDs have been assigned.

Has Tenable released any product coverage for these vulnerabilities?

No. Once CVE IDs are assigned and patches are released, this post will be updated with plugin links. As always, customers can expect that forthcoming plugins will appear in the Plugins Pipeline as they are released.

Get more information

Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.

Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

Author

Learn more