Back

Citrix NetScaler Zero-Day Flaws Prompt Urgent Shutdown Warnings

At a glance

  • Two unpatched zero-day vulnerabilities found in Citrix NetScaler ADC and Gateway.
  • Dutch National Cyber Security Centre advised immediate shutdown of affected appliances.
  • No official Citrix advisory or patch released as of September 27, 2026.

Active exploitation of two previously unknown vulnerabilities in Citrix NetScaler ADC and Gateway was reported on September 25, 2026, leading to urgent operational guidance for administrators. The incident has resulted in widespread attention from cybersecurity professionals and organizations using these products.

Security researchers and users on Reddit identified that the vulnerabilities were being exploited before any official patch or advisory had been released by Citrix. The Dutch National Cyber Security Centre (NCSC-NL) reportedly distributed a pre-notification under TLP:AMBER+STRICT, instructing organizations to power down their NetScaler appliances as a precautionary measure.

Administrators participating in online discussions stated that they received calls from IT suppliers, who relayed instructions to immediately shut down NetScaler devices. These instructions were attributed to information received from NCSC-NL, and referenced two critical remote code execution vulnerabilities that did not yet have assigned CVE identifiers or severity ratings.

According to public reporting as of September 27, 2026, Citrix had not yet published an official advisory or patch for the affected products. However, multiple sources indicated that patches were anticipated to become available during the week of September 28, 2026.

What the numbers show

  • Reports of exploitation surfaced on September 25, 2026.
  • As of September 27, 2026, no patch or official advisory had been released by Citrix.
  • Patches were expected to be available in the week of September 28, 2026.

In a Reddit discussion, one user stated that Citrix was preparing to release patches early in the following week. The same user indicated that the NCSC-NL's pre-notification was issued under the Cyber Resilience Act reporting framework, emphasizing the regulatory context of the response.

The vulnerabilities in question have not yet been assigned CVE IDs, and no public proofs-of-concept or indicators of compromise have been made available. This lack of public technical details has contributed to the urgency of the shutdown recommendations from IT suppliers and national cybersecurity authorities.

At the time of reporting, organizations relying on Citrix NetScaler ADC and Gateway appliances were advised to follow the guidance provided by their IT suppliers and national cybersecurity authorities. The situation remained dynamic as administrators awaited further updates from Citrix regarding official remediation steps.

* This article is based on publicly available information at the time of writing.