# Two Unpatched Citrix NetScaler 0‑Day Exploits Are Being Used in Real‑World Attacks, Researchers Warn

*Sunday, September 27, 2026 at 8:07 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-27T08:07:55.779Z (1h ago)
**Category**: cyber | **Region**: Global
**Importance**: 9/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/18958.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Researchers say attackers are exploiting two unpatched remote‑code‑execution flaws in Citrix NetScaler, while Citrix has yet to confirm the bugs, identify affected versions, or issue workarounds or compromise indicators.

Organisations that rely on Citrix NetScaler now face a serious blind spot after security researchers reported that two zero‑day vulnerabilities in the product are being exploited while no vendor fixes are available.

Researchers at watchTowr said the flaws are remote‑code‑execution (RCE) vulnerabilities and that they are already seeing exploitation in the wild. RCE bugs allow an attacker to run their own code on a targeted device, which in this case is a widely used application delivery product that often sits at the edge of corporate networks.

Citrix, for now, has not confirmed the vulnerabilities or published technical details. The company has not released patches, listed affected versions, offered workarounds, or shared indicators of compromise that could help defenders spot intrusions.

That lack of guidance leaves administrators guessing about their exposure. NetScaler appliances frequently handle traffic between the internet and internal business applications. When such a device has an unpatched RCE bug and is reachable from the outside, it can become a direct entry point into an organisation’s network.

Security teams responsible for NetScaler instances that support remote access or other critical services face uncomfortable choices. Restricting or temporarily shutting down external access can reduce risk but may disrupt business operations. Leaving services fully exposed while the underlying vulnerabilities remain unaddressed increases the chance that attackers will secure a foothold before official mitigations arrive.

Sectors that depend heavily on secure application delivery, such as government and large enterprises, have particular reason for concern because a compromise on a NetScaler device can open paths toward sensitive systems and data deeper inside the network.

Defenders can still take some practical steps while waiting for vendor information. Network teams can tighten access controls around NetScaler, limit which interfaces are exposed to the internet, and increase scrutiny of logs for unusual activity originating from or passing through these devices. Stronger network segmentation can make it harder for an attacker to move from a compromised appliance to the rest of the environment.

Key developments to watch include whether Citrix issues a formal advisory with technical details and mitigation steps, whether national cyber agencies amplify the warning about active exploitation, and whether incident‑response firms begin linking specific breaches to these NetScaler flaws.
