What the NetScaler Zero-Days Are and How They're Being Exploited

Security research firm watchTowr says two unpatched remote code execution (RCE) vulnerabilities in Citrix NetScaler have already been exploited in the wild, and Citrix is not expected to ship fixes until early next week. That gap between confirmed exploitation and an available patch is what makes this a genuine zero-day event rather than a routine bug disclosure: attackers currently have a working path into affected systems, and defenders have no official fix to apply yet.

NetScaler, formerly known as Citrix ADC, is widely deployed as an application delivery controller and remote access gateway. Organizations use it to manage traffic to internal applications, enforce load balancing, and, critically, to provide secure remote access, functioning much like a VPN gateway for employees and partners connecting from outside the corporate network. Because these appliances sit at the edge of a network, facing the public internet by design, an RCE flaw in NetScaler gives an attacker a foothold that can be far more damaging than a bug buried deep inside an internal application. Once inside, an attacker doesn't need to breach individual employee accounts; they can potentially move laterally across whatever the appliance was trusted to protect.

Details on the exact exploitation techniques are still limited, which is typical in the early days of a zero-day disclosure. What matters for now is that watchTowr, a firm with a track record of tracking exploited network appliance flaws, has confirmed active exploitation, and Citrix has acknowledged the issue is serious enough to warrant an expedited patch timeline.

Why Enterprise VPN Gateway Flaws End Up Hurting Consumer Privacy

It's easy to read a headline about an enterprise networking appliance and assume it's a problem for IT departments, not everyday internet users. But remote access gateways like NetScaler are often the front door to the very systems that store customer data: billing records, health information, login credentials, and more. When attackers gain unauthorized code execution on a device like this, they aren't just disrupting network traffic. They're potentially gaining a launch point to reach databases, internal file shares, and authentication systems that hold personal information belonging to customers who have no direct relationship with the vulnerability at all.

This is a pattern that shows up repeatedly in zero-day incidents involving edge infrastructure. Our explainer on how zero-day attacks unfold breaks down why the window between discovery and patch availability is the most dangerous phase of any vulnerability's lifecycle, and why attackers race to exploit it before defenders can respond. Reports on China-aligned threat groups racing to exploit shared zero-day chains show how quickly sophisticated actors pivot to newly disclosed flaws once they become public knowledge, which is exactly the risk window NetScaler customers are in right now.

Who's at Risk While Citrix Finalizes a Patch

Any organization running an unpatched, internet-facing NetScaler appliance is potentially exposed until Citrix's fix lands. That includes enterprises across industries that rely on NetScaler for secure remote access and application delivery, meaning employees, contractors, and customers connected through these systems could all be downstream of an incident if an attacker succeeds in exploiting one of these flaws before a patch is applied.

Because patch details and CVE identifiers for this specific pair of flaws had not been finalized publicly at the time of watchTowr's report, organizations should treat any NetScaler deployment as a priority to monitor closely rather than wait for a formal advisory to act. Vulnerabilities that reach this level of active exploitation typically get added to government tracking lists once confirmed; our recent roundup on flaws added to the CISA known exploited vulnerabilities list is a useful reference for understanding how that federal tracking process works and how to check whether a product your organization uses has been flagged.

What This Means For You

If you work in IT or security operations, the priority right now is visibility: know which NetScaler appliances your organization runs, confirm their exposure to the internet, and watch for Citrix's official advisory and patch release expected early next week. Applying the patch as soon as it's available should be treated as urgent, not routine maintenance.

If you're a consumer, there's no immediate action to take, since this is an enterprise infrastructure issue rather than a direct-to-consumer product flaw. But it's a reminder that the security of your personal data often depends on decisions made by IT teams at companies you interact with, decisions like how quickly they patch edge devices that face the open internet.

Key Takeaways

  • Two unpatched NetScaler RCE zero-days are confirmed to be under active exploitation, according to watchTowr.
  • Citrix is expected to release patches early next week; until then, affected appliances remain exposed.
  • IT teams should inventory NetScaler deployments now and apply the patch immediately once it's released.
  • Consumers should understand that enterprise gateway flaws like this one are part of why the companies holding your data need strong, fast patching practices, even if you never see the vulnerability directly.

Staying informed about NetScaler zero-day exploited incidents like this one, and understanding how quickly attackers move once a flaw becomes known, is one of the simplest ways to gauge how seriously the companies you trust with your data are taking their own security.