Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Two Unpatched Citrix NetScaler Zero-Days Under Active Exploitation: A Growing Concern for Enterprise Networks




Two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances have been actively exploited in the wild, posing a significant risk to organizations that rely on these devices for network security. With Citrix's existing guidance in place, administrators are advised to take immediate action to protect their networks and stay informed about the latest security updates and patches.

  • Two unpatched zero-day vulnerabilities (CVE-2026-19490 and CVE-2026-19491) have been found in Citrix NetScaler ADC and NetScaler Gateway appliances.
  • The vulnerabilities enable remote code execution and have been actively exploited in the wild, posing a significant risk to organizations.
  • Citrix is expected to address the vulnerabilities in the coming days, but administrators are advised to take immediate action to protect their networks.
  • The impact of the zero-day vulnerabilities can be severe, including unauthorized access, data theft, and business disruption.
  • Administrators are advised to take proactive measures, such as powering off appliances, isolating them from the network, and changing passwords.
  • Citrix's existing guidance for suspected NetScaler compromise is limited, and the fate of older builds remains uncertain.
  • The incident highlights the importance of regular security updates and the need for organizations to stay vigilant in the face of emerging threats.



  • The threat landscape for enterprise networks has taken a significant hit with the revelation of two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances. According to security firm watchTowr, these vulnerabilities, CVE-2026-19490 and CVE-2026-19491, have been actively exploited in the wild, posing a significant risk to organizations that rely on these devices for VPN, remote access, load balancing, and user authentication.

    The two vulnerabilities, both of which enable remote code execution, were discovered during forensic investigations and are expected to be addressed by Citrix in the coming days. However, with the existing guidance from Citrix, which includes preserving evidence, isolating the appliance from the network, changing service account passwords, and revoking certificates and private keys, administrators are advised to take immediate action to protect their networks.

    The impact of these zero-day vulnerabilities cannot be overstated, as they can be used to gain unauthorized access to the network, steal sensitive data, and disrupt business operations. In 2025, the Netherlands' National Cyber Security Center warned that updating alone did not remove the risk of a zero-day vulnerability, as an attacker could retain access gained before a patch was applied.

    To mitigate this risk, administrators are advised to take proactive measures, such as powering off the appliances, isolating them from the network, and changing passwords. The Dutch agency's 2025 check scripts, which cover a live appliance, core dumps, and full NetScaler images, can also be used to identify potential vulnerabilities.

    Citrix has not confirmed the existence of these vulnerabilities or published a fix, leaving administrators with limited options for protection. The company's existing guidance for a suspected NetScaler compromise is clear, but the question remains whether all versions of NetScaler will receive a fix, including older builds such as 13.1-73.32 and 13.1-63.21.

    The threat of unpatched zero-day vulnerabilities highlights the importance of regular security updates and the need for organizations to stay vigilant in the face of emerging threats. As the threat landscape continues to evolve, it is essential for administrators to stay informed and take proactive measures to protect their networks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Two-Unpatched-Citrix-NetScaler-Zero-Days-Under-Active-Exploitation-A-Growing-Concern-for-Enterprise-Networks-ehn.shtml

  • https://thehackernews.com/2026/09/warning-two-unpatched-citrix-netscaler.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-19490

  • https://www.cvedetails.com/cve/CVE-2026-19490/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-19491

  • https://www.cvedetails.com/cve/CVE-2026-19491/


  • Published: Sun Sep 27 04:06:50 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us