watchTowr reported that attackers may be actively exploiting two unpatched remote-code-execution vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances. Citrix had not confirmed the claims or published CVE IDs, affected versions, indicators of compromise, technical details, or fixes, leaving the reports unverified but potentially severe because the appliances commonly serve as internet-facing application-delivery and VPN gateways.
Organizations should inventory NetScaler deployments, restrict or remove unnecessary external and management access, preserve authentication and administrative logs, and monitor exposed appliances for signs of compromise. Teams should be prepared to isolate internet-facing systems where residual risk is unacceptable and rapidly apply Citrix guidance when available; the reported flaws are separate from the vendor's August advisory for actively exploited authentication-bypass vulnerability CVE-2026-19490 and denial-of-service flaw CVE-2026-19489.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
watchTowr publicly warned that reports indicated multiple unpatched remote-code-execution vulnerabilities in Citrix NetScaler ADC and Gateway appliances. The reported flaws were allegedly identified during forensic investigations and exploited in real-world attacks, but Citrix had not confirmed them, assigned CVEs, or released fixes.
Organizations reportedly began shutting down or isolating some internet-exposed NetScaler appliances following the unconfirmed RCE zero-day reports and national-authority guidance.
NCSC-NL reportedly issued a pre-notification to organizations regarding two unpatched Citrix NetScaler ADC and Gateway vulnerabilities, assessing that each could independently permit unauthenticated remote code execution. One reported flaw allegedly enables direct in-memory shellcode execution; neither issue had a public CVE, patch, or confirmed indicators of compromise at the time described.
CISA added Citrix NetScaler authentication-bypass vulnerability CVE-2026-19490 to the Known Exploited Vulnerabilities catalog.
Singapore's Cyber Security Agency warned that exploitation attempts targeting the NetScaler authentication-bypass vulnerability CVE-2026-19490 had been observed.
Citrix published a bulletin covering CVE-2026-19490, a critical authentication-bypass flaw under active exploitation, and CVE-2026-19489, a memory-overflow denial-of-service vulnerability. The bulletin provided fixed NetScaler ADC and Gateway versions and stated there was no workaround.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
thecybersecguru.com
Open sourcecybersecuritynews.com
Open sourcelabs.beazley.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.