Citrix NetScaler ADC and Gateway Hit by Two Critical Zero‑Day RCE Flaws Exploited in the Wild
What Happened — Citrix disclosed that two previously unknown critical vulnerabilities in its NetScaler ADC and NetScaler Gateway appliances were actively exploited before patches were available. Both flaws enable remote code execution, allowing an attacker to take full control of the affected appliance.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of gaps in vulnerability‑management and patch‑remediation processes – a core control objective for continuous assurance programs.
- Highlights the need for real‑time monitoring of vendor advisories and documented evidence that patches are applied within defined service‑level windows.
- Provides a concrete example of why organizations must maintain a defensible audit trail of remediation actions to satisfy multiple frameworks (e.g., NIST CSF, ISO 27001).
Who Is Affected – Enterprises and service providers that deploy Citrix NetScaler ADC or Gateway, spanning technology, finance, healthcare, and other sectors that rely on application delivery controllers.
Recommended Actions
- Immediately isolate unpatched NetScaler appliances and apply the September 27 patches.
- Deploy automated vulnerability scanning that includes Citrix products and integrates findings into your control‑evidence repository.
- Document remediation steps (ticketing, change‑control records) to support audit readiness.
Source: Security Affairs
Technical Notes
- Both flaws are remote code execution (RCE) vulnerabilities; one permits direct shellcode injection into memory.
- The issues are distinct from previously disclosed CVE‑2026‑19490 and CVE‑2026‑19489.
- Exploitation was confirmed by third‑party researchers and national CERTs before Citrix issued patches.
Source: Security Affairs