Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

A devastating pair of zero-day vulnerabilities in Citrix NetScaler has put thousands of organizations worldwide at risk, with attackers actively exploiting the flaws to gain remote access and wreak havoc on networks. The situation is dire, with security experts warning that the compromised systems are being used as a springboard for further attacks, highlighting the importance of prompt patching and vigilance.

The affected Citrix NetScaler products, used by over 300,000 organizations globally, contain two unpatched remote code execution (RCE) vulnerabilities. These flaws allow attackers to inject malicious code into a system, effectively granting them complete control. The problem lies in the way NetScaler handles HTTP requests, which can be manipulated to bypass security checks and execute arbitrary code on the affected server. In other words, an attacker can send a specially crafted request that tricks the system into running their own code, giving them unfettered access.

Citrix is quick to emphasize that only systems running specific versions of NetScaler are vulnerable, but this is cold comfort for the many organizations still using outdated software or failing to apply regular security updates. It’s estimated that around 20% of all affected systems have yet to receive a patch, leaving them exposed to cyber threats. The situation is compounded by the fact that attackers can exploit these vulnerabilities even without a user clicking on a malicious link or downloading an attachment – making it extremely difficult for organizations to detect and prevent the attacks.

The exploitation of these zero-days highlights the alarming rate at which vulnerabilities are being discovered and used in real-world attacks. With the ever-growing sophistication of cyber threats, security teams must stay vigilant and prioritize patching and vulnerability management. Failure to do so can have catastrophic consequences, as we’ve seen time and time again. In this case, Citrix is urging affected organizations to apply the latest patches immediately, but for those who have yet to receive them, the window of opportunity is rapidly closing.

As the cybersecurity landscape continues to evolve at breakneck speed, one thing remains constant: the importance of staying ahead of emerging threats. By prioritizing security and keeping software up-to-date, organizations can significantly reduce their exposure to cyber risks. With the stakes so high, it’s imperative that all parties take immediate action to mitigate these vulnerabilities and prevent further exploitation.

In practical terms, readers should be aware of their organization’s vulnerability landscape and ensure that all systems are running the latest security patches. This includes not only Citrix NetScaler but also other software and applications that may be affected by similar vulnerabilities. By taking a proactive approach to security and staying informed about emerging threats, organizations can better protect themselves from the ever-present threat of cyber attacks.


Source: The Hacker News — 2026-09-27