Citrix NetScaler zero-day remote code
Two unpatched remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway appliances are under active exploitation, with no vendor patch or

Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are being actively exploited in the wild. Security firm watchTowr reported the active exploitation of these remote-code-execution flaws on September 26, later confirming forensic investigations had uncovered two distinct vulnerabilities exploited before a patch existed. WatchTowr first warned about credible reports of the flaws in a social media post that day.
Vendor response and technical uncertainty
Citrix and its parent company, Cloud Software Group, have not confirmed the vulnerabilities, issued a fix, or published any indicators of compromise. As of September 27, no security advisory had been released. The vendor has provided no workaround and has not clarified which appliance versions are affected. It remains open whether builds 14.1-73.32 and 13.1-63.21 released in August, or any newer releases, are vulnerable. Citrix has also not stated if the older NetScaler 13.1 branch will receive a fix for these new flaws.
Community response and operational dilemmas
Facing the void of official guidance, some administrators have taken drastic action. Reports on a technical forum described security providers advising customers to shut down NetScaler appliances immediately on September 26. One administrator wrote that their IT supplier's security team phoned to advise an immediate shutdown but provided no technical details. Other commenters confirmed their organizations had taken similar steps. The ultimate source of this shutdown advice remains unconfirmed.
Organizations must now assess the risk of keeping appliances online while awaiting vendor guidance. Teams able to remove NetScaler from service should prepare for isolation. Those that must keep it online are advised to restrict access, remove internet-facing management interfaces, and increase monitoring. Managed-service providers should be asked to identify the source of any shutdown advice before critical operational decisions are made. Until Citrix publishes technical guidance, organizations should document their NetScaler versions, internet exposure, backup access paths, and emergency shutdown procedures.
Existing guidance and forensic limitations
NetScaler ADC and NetScaler Gateway handle VPN, remote access, load balancing, and user authentication at the edge of enterprise networks. Citrix's existing guidance for a suspected compromise, which predates these specific flaws, outlines several critical steps. It advises administrators to first preserve evidence by taking a snapshot of the VPX instance, securing logs on remote syslog servers and the NetScaler Console, gathering a technical support bundle, and capturing a core dump of the packet engine. The appliance should then be isolated from the network. Every service account password and secret stored on it must be changed, and passwords for users who signed in through it should be reset. Its certificates and private keys must be revoked. The management interface should be kept off the internet.
Detection options are limited. Scripts provided by a national cybersecurity agency in 2025 offer a further option for checking a live appliance, core dumps, and full NetScaler images, but with important caveats. The README for the live-appliance script states it looks for files that indicate compromise but is not specific to one vulnerability. The agency does not guarantee its effectiveness in finding every intrusion. This code received its last update in September 2025. A clean result from the script cannot definitively clear an appliance, especially if logs are incomplete or the system was altered before examination.
The exploitation occurred before any fix existed. This means installing a future patch will not reveal whether an attacker gained access first. The decision for anyone running a NetScaler is now whether to keep it online, isolate it, or power it off, and whether to treat it as already compromised. Organizations must assess risk of keeping appliances online while awaiting vendor guidance.





