Threat Brief — 2026-09-27 — Citrix NetScaler Zero-Days Exploited
Two unpatched remote code execution zero-days in Citrix NetScaler ADC and NetScaler Gateway are under active exploitation in the wild, with no vendor patch yet available. Security firm watchTowr disclosed the vulnerabilities on September 26, and Citrix has not confirmed a remediation timeline. This is the most urgent item today: internet-exposed NetScaler appliances are at immediate risk of compromise while no fix exists.
Top items
- Two unpatched Citrix NetScaler RCE zero-days actively exploited. watchTowr reported that two new zero-day vulnerabilities allowing remote code execution in Citrix NetScaler ADC and NetScaler Gateway appliances are being exploited in the wild. Citrix has not yet released patches, leaving exposed appliances with no vendor remediation option. Mitigation guidance has not been detailed in the available reporting; organisations running NetScaler should monitor for Citrix advisory updates and consider isolating affected appliances from the internet until patches ship. (src: The Hacker News)
Themes
Unpatched edge appliances under active attack. The Citrix NetScaler disclosure fits a broader pattern observed this month of threat actors targeting perimeter infrastructure before patches are available — consistent with the ongoing Cisco FMC exploitation (CVE-2026-20079KEV) and the Kiteworks shutdown advisory. Attackers continue to prioritise externally exposed appliances as high-value entry points.
