Citrix admins warned to shut down NetScalers over 2 exploited zero-days

Citrix Administrators Urged to Shut Down NetScaler Appliances Amid Reports of Exploited Zero-Days

Cybersecurity agencies and IT providers have been privately warning organizations about two unpatched zero-day vulnerabilities in Citrix NetScaler appliances, with some administrators reporting that they’ve received calls from law enforcement and national cybersecurity agencies advising them to shut down their systems immediately. The situation highlights the urgent need for prompt patching of known vulnerabilities, as well as the importance of having incident response plans in place.

The warning is related to two previously unknown remote code execution (RCE) vulnerabilities in Citrix NetScaler, which have reportedly been exploited in attacks. These vulnerabilities are distinct from CVE-2026-19490 and CVE-2026-19489, two other flaws disclosed by Citrix in August that were also being actively exploited. The fact that these new zero-days have already been used in attacks underscores the importance of staying vigilant and up-to-date with patches.

The Dutch National Cyber Security Center (NCSC-NL) has issued a pre-notification advisory to organizations in the Netherlands, providing additional details about the vulnerabilities. According to the notice, each vulnerability can independently lead to RCE, with one allowing attackers to directly inject shellcode into memory. The NCSC is working closely with Citrix to obtain technical information and possible indicators of compromise (IoCs) related to the incident.

Citrix administrators have reported that IT suppliers and security teams are contacting their organizations, advising them to shut down their NetScaler appliances as a precautionary measure. This proactive approach is aimed at minimizing potential damage while patches are being prepared for release next week. The NCSC’s pre-notification advisory serves as a reminder to organizations to prioritize patching and incident response planning.

The situation also highlights the importance of transparency in cybersecurity reporting, with some administrators sharing copies of the NCSC notification online. While Citrix has not publicly confirmed the existence of these zero-days, their expected patches next week will undoubtedly provide much-needed relief to affected organizations.

As a practical takeaway for readers, this incident underscores the need for prompt patching and ongoing monitoring of systems. Organizations should consider implementing safeguards where possible, such as using network segmentation or intrusion detection systems, to minimize potential damage. Furthermore, having an incident response plan in place can help ensure swift action is taken in the event of a security breach. With the expected release of patches next week, organizations are advised to prepare for downtime and implement patches quickly to mitigate any potential risks associated with these zero-day vulnerabilities.


Source: Bleeping Computer — 2026-09-27