NetScaler users are scrambling to assess their risk and exposure amid as-yet-unconfirmed reports that a new pair of RCE zero days are being exploited.
Citrix NetScaler appliances are widely used by major banks, governments and other organisations as a gateway (VPN virtual server, ICA proxy, CVPN, or RDP proxy), a AAA virtual server, or depending on configuraiton, other critical network uses.
Attack surface management firm watchTowr warned that it believed “multiple unpatched Citrix NetScaler RCE vulnerabilities are circulating in the wild” – saying it had “high confidence” in this and had “verified it with authoritative sources.”
The Dutch NCSC is rumoured to have been contacting those with exposed instances under TLP: Amber restrictions. It has yet to publish a public advisory with details.
A since-deleted version of the alleged NCSC advisory posted online, suggested that “The zero-day vulnerabilities were discovered during an investigation by Citrix at customer environments following reports of disruptions… Exploitation has been identified at multiple Citrix customers worldwide. The NCSC does not currently know whether these zero-day vulnerabilities are being exploited on a widespread scale.”
“One of the vulnerabilities involves placing shellcode in memory. Similar techniques have previously been observed with critical Citrix NetScaler vulnerabilities.”
The Stack could not confirm the legitimacy of the detail-thin advisory and has contacted the Dutch NCSC for comment. Citrix has yet to comment publicly.
For now, users have no insight on build versions and configurations potentially affected. Multiple users on the NetScaler /r/Citrix sub-Reddit said they were receiving the same following message from Citrix: “Our teams are working around the clock to develop a fix to address the recently identified Netscaler vulnerabilities and expect to have an update to share soon”. The Stack could not independently confirm this. Several users suggested Citrix was planning to push an advisory by 22:00 CET.
NetScaler exploitation... is pretty common
NetScaler appliances are regularly attacked: recent examples of vulnerabilities that have been targeted by hackers this year alone include authentication bypass bug CVE-2026-19490, and memory overflow bugs CVE-2026-8452 and CVE-2026-3055.
(NetScaler appliances were also exploited at massive scale by threat groups abusing “CitrixBleed” in 2023, aka CVE-2023-4966 – a bug that let attackers grab valid session tokens from internet-facing NetScaler devices’ memory. These could be used to hijack active sessions, bypassing MFA. The likes of Boeing and the world’s largest bank, China’s ICBC were breached during that threat campaign by a ransomware group.)
As The Stack noted earlier this summer, NetScaler and many other network appliances are riddled with ageing and insecure code/sometimes underlying operating systems; critics warn that similar classes of exploitable vulnerability will keep rearing their heads despite widespread industry “Secure by Design” pledges.
Ripping and replacing NetScaler is typically not a trivially undertaken option.
Depending on deployment configuration, that can involve things like re-engineering how external and internal DNS failover mechanisms operate; auditing and recoding thousands of lines of configuration files into F5 iRules, Nginx configurations, or cloud-native load balancer rules (depending on which frying pan looks preferable to the fire); feature teh risk of breaking tortuous firewall access control lists (ACLs) and generally rearchitecting AAA (Authentication, Authorisation, Auditing) policies.
We will update this article with details when we get them.
Have further insight/affected? ed@thestack.technology