Security · 4 MIN READ

Two Reported NetScaler RCE Zero-Days: An Exposure and Evidence Checklist

watchTowr says two unpatched remote-code-execution vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway are being actively exploited. With Citrix yet to confirm the flaws or release fixes, engineering teams should identify exposed appliances, consider proportionate isolation, and preserve evidence before making disruptive changes.

Two Reported NetScaler RCE Zero-Days: An Exposure and Evidence Checklist

What Has Been Reported

Security firm watchTowr said on September 26 that two new zero-day vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances were under active exploitation. The reported flaws allow remote code execution and remained unpatched when the report was published.

At that point, Citrix had not confirmed the vulnerabilities or released a fix. Some administrators reportedly chose to take affected appliances offline rather than continue operating them while awaiting vendor guidance.

These details matter because the report does not provide a basis for assuming that every appliance is compromised. It does, however, justify an urgent, evidence-led review of the relevant environment.

Do not invent CVE identifiers, affected versions, indicators of compromise, or remediation commands while vendor confirmation is pending. Base decisions on verified asset data, trusted intelligence, and documented risk acceptance.

Immediate Engineering Priorities

1. Establish the scope

Start with an authoritative inventory rather than relying on memory or addressing conventions. Identify:

  • All NetScaler ADC and NetScaler Gateway appliances.

  • Their operational roles, owners, locations, and dependencies.

  • Which systems can reach their management and service interfaces.

  • Whether any instances are dormant, temporary, or maintained outside the normal change process.

  • The business services that would be affected by isolation or shutdown.

Record the time of the assessment and the information used. The inventory may change as additional appliances or dependencies are discovered.

2. Reduce exposure proportionately

Evaluate whether each appliance can be isolated, have access paths restricted, or be taken offline. The appropriate action depends on business criticality, available redundancy, and the organization's incident-response policy.

Before changing connectivity:

  • Obtain the required emergency-change authorization.

  • Document the appliance's current state and network relationships.

  • Plan an alternative path for critical services where one exists.

  • Avoid broad, untested changes that could create a second outage or erase useful evidence.

Isolation is a containment decision, not proof that an appliance was compromised and not a substitute for a future vendor fix.

3. Preserve evidence before remediation

Where operational and forensic procedures permit, preserve available evidence before rebooting, wiping, replacing, or reconfiguring an appliance. Useful records can include:

  • Current and previous configuration snapshots.

  • Available device and security logs.

  • Administrative access records.

  • Change tickets and automation-job histories.

  • Accurate timestamps for discovery, isolation, collection, and subsequent actions.

Store collected material in a controlled location and document who collected it. If compromise is suspected, involve the incident-response or forensic team so that evidence handling follows organizational requirements.

4. Separate containment from recovery

A previous configuration can help reverse an unauthorized or damaging change, but it cannot patch a zero-day vulnerability. Treat rollback, isolation, credential review, evidence collection, and eventual patching as separate activities with distinct objectives.

Once Citrix publishes confirmed guidance, teams should validate the affected scope, test the prescribed remediation, deploy it through controlled change procedures, and reassess appliances before restoring normal connectivity.

How ConnectMyAssets Helps

ConnectMyAssets provides an on-prem, vendor-agnostic control point for managing the surrounding assessment and response workflow:

  • Dynamic CMDB: Locate recorded NetScaler appliances, identify owners and roles, and map related infrastructure that may be affected by isolation.

  • Topology: Review dependencies before disconnecting an appliance or modifying network paths.

  • Backup & History: Preserve configuration versions, compare changes, and maintain a timeline of known configuration state. One-click rollback can restore a known configuration where appropriate, but it does not remediate the reported vulnerabilities.

  • Per-asset CVE Tracking: Associate official vulnerability records with individual assets once identifiers and validated advisories become available. No placeholder CVEs should be created from unconfirmed information.

  • Compliance Engine: Record assessment, approval, containment, and remediation evidence against internal controls and frameworks such as NIS2, ISO 27001, PCI, CISA, or NIST requirements.

  • Automation: Execute approved, tested changes across supporting infrastructure where integrations permit, while retaining a consistent change trail. Emergency automation should remain scoped and reversible.

  • SSH Bastion and Credential Vault: Centralize controlled administrative access and reduce the need to distribute infrastructure credentials during incident response.

Because ConnectMyAssets runs on premises, asset, configuration, and compliance data can remain within the organization's environment while teams coordinate their response.

What to Watch Next

Engineering teams should monitor Citrix communications and trusted security reporting for:

  • Confirmation of the reported vulnerabilities.

  • Official identifiers and affected product information.

  • Vendor-provided mitigations or fixes.

  • Validated detection guidance and indicators of compromise.

  • Instructions for safely returning isolated appliances to service.

Until those details are available, maintain a clear distinction between confirmed facts, third-party reporting, local observations, and assumptions. That discipline helps teams contain risk without damaging evidence or creating unsupported remediation steps.


Source: The Hacker News

Share this articleLinkedIn ↗Email ↗

Keep exploring.

All articles →
Security

F5 Fixes Actively Exploited BIG-IP APM Zero-Day

F5 has released hotfixes for CVE-2026-94127, a critical BIG-IP APM vulnerability already exploited in the wild. Network teams should identify systems configured as OAuth authorization servers, apply the appropriate fix or interim mitigation, and retain evidence showing that remediation was completed.

Read article