Two newly uncovered, unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited in the wild, according to watchTowr. Administrators are being urged to isolate or shut down appliances while awaiting Citrix guidance, as no fix, workaround, or indicators of compromise have yet been published. #Citrix #NetScalerADC #NetScalerGateway #watchTowr
Keypoints
- Two unpatched zero-days in Citrix NetScaler can enable remote code execution.
- watchTowr says the flaws are being exploited in the wild.
- Citrix has not yet confirmed the vulnerabilities or released a fix.
- Some administrators are taking NetScaler appliances offline as a precaution.
- Citrix advises preserving evidence, isolating the appliance, and rotating credentials after suspected compromise.
Read More: https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html