- September 26, 2026
Unconfirmed NetScaler Zero-Day Prompts Emergency Shutdowns
On September 26th, 2026, security researchers from watchTowr publicly warned that it had verified reports of multiple unpatched remote code execution vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway, as organizations began taking the appliances offline on the advice of national authorities.
Executive Summary
On September 26th, 2026, security researchers from watchTowr publicly warned that it had verified reports of multiple unpatched remote code execution vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway, as organizations began taking the appliances offline on the advice of national authorities. The reported flaws have not been assigned CVE identifiers, and as of publication Citrix nor the Netherlands' National Cyber Security Centre (NCSC-NL) has released an advisory confirming them.
NetScaler ADC and NetScaler Gateway are internet-facing application delivery and VPN appliances that serve as the remote-access entry points for enterprise environments. While reports have not been confirmed by Citrix and NCSC-NL, the potential impact is severe, and the affected product sits at the network perimeter.
Beazley Security recommends affected organizations follow the guidance of their national cyber authority, restrict or disable external access to NetScaler appliances until a fix is released, and monitor closely for signs of compromise.
Affected Systems or Products
Citrix NetScaler ADC and NetScaler Gateway are the products named in the current reports. No specific affected firmware builds or configurations have been confirmed, so the full scope is not yet established. Any internet-facing NetScaler ADC or Gateway deployment should be treated as potentially in scope until Citrix publishes details.
Mitigations / Workarounds
With no patch available and the reports unconfirmed, remediation is not yet possible, and the priority is to reduce exposure and preserve the ability to investigate. Beazley Security suggests the following interim steps:
- 1.
Consider taking internet-facing NetScaler ADC and Gateway appliances offline, or restricting their access to trusted and administrative networks, until Citrix confirms the issue and releases a fix.
- 2.
Increase monitoring and retention of authentication and administrative logs to support later investigation.
Patches
At the time of writing, no patch is available for the vulnerabilities described in these reports, and Citrix has not published an advisory addressing them. Organizations should watch for an official Citrix advisory and apply any fix as soon as it is released.
How Beazley Security is responding
Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found. If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team