On September 26, security firm watchTowr said two unpatched vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited, both allowing remote code execution. Citrix has not confirmed the flaws or published a fix. watchTowr says the flaws were discovered during forensic investigations and exploited before any fix existed, but it has published no evidence, named no victim, or identified whose investigations found the exploitation.

The new flaws are separate from CVE-2026-19490, an authentication bypass Citrix patched on August 19 and CISA added to its Known Exploited Vulnerabilities catalog on September 9. Citrix has not said whether appliances on the August builds or newer are affected. With no vendor bulletin, there are no workarounds or indicators of compromise. Some administrators on Reddit said their IT suppliers advised shutting NetScalers down immediately; others said their organizations had done so.

Until a fix arrives, operators must decide whether to keep a NetScaler online, isolate it, or power it off, and whether to treat it as already compromised. Because exploitation happened before any fix existed, installing a future patch will not reveal whether an attacker got in first. Citrix's existing guidance for suspected compromise includes preserving evidence, isolating the appliance, rotating credentials, and keeping the management interface off the internet. The Dutch NCSC's 2025 check scripts are another option, though they come with no guarantee of effectiveness.