Skip to content
Rush Commerce
Field Notes4 min read

NetScaler zero-days: no CVE, no patch, turn it off

Two NetScaler zero-days are being exploited with no CVE, no Citrix advisory, and no patch. The EU's new 24-hour clock means you will get warned like this again.

Over the weekend, a lot of teams got the same instruction from their MSP: shut the NetScaler off. Not patch it. Not filter it. Power it down. There is no CVE. There is no Citrix advisory. There is no patch. That combination is new, and it is going to keep happening — so it is worth understanding what you are actually being asked to act on.

What actually happened

Per BleepingComputer and Tenable's FAQ:

  • Two unpatched remote code execution flaws in NetScaler ADC/Gateway are being exploited in the wild. Each is independently sufficient for code execution; one reportedly places shellcode directly into memory.
  • No CVE identifiers have been assigned and no CVSS scores exist. Tenable lists both as "Not Assigned."
  • The Dutch NCSC sent a pre-notification to Netherlands organizations under Traffic Light Protocol restrictions before September 25, based on active exploitation found across multiple Citrix customers during incident response. Tenable notes it has not independently reviewed that notice — the details reaching you have passed through several hands.
  • watchTowr confirmed awareness on September 26 and pointed everyone at the vendor: "Please, direct further questions to Citrix. We are not Citrix PSIRT."
  • As of September 27, Citrix has published nothing. Patches are anticipated early in the week of September 28, per public reporting.
  • The advice is containment, not mitigation. Shut down internet-exposed appliances where you can, otherwise restrict access to trusted networks and IPs. Never expose the management interface. There are no indicators of compromise to hunt for yet.

Why a pre-patch warning matters for your business

This is what the new reporting clock looks like from the receiving end. On September 11, the EU Cyber Resilience Act's reporting obligations took effect. Manufacturers of products with digital elements sold in the EU must file an early warning with ENISA's Single Reporting Platform within 24 hours of learning an exploited vulnerability exists — 72 hours for detail, and a final report within 14 days of a fix. Penalties top out at €15 million or 2.5% of global turnover. Read the European Commission's own summary if you sell software into the EU; the obligation applies to legacy products too.

The structural consequence: regulators and CERTs now know about exploited bugs before the public does, and before a patch exists. Some of them tell their constituencies. So the alert you receive will increasingly be a vendor-less, CVE-less "turn it off" — arriving days ahead of anything you can apply.

Your runbook probably assumes a patch exists. Most vulnerability processes are a pipeline: CVE lands, severity gets scored, a ticket gets cut, a maintenance window gets booked. None of that has an input here. The only question that matters is whether you can take a specific appliance off the internet inside an hour, and whether you know what breaks when you do.

So find out before you need to. For every internet-facing appliance — VPN concentrator, load balancer, file transfer box, mail gateway — write down three things: who can shut it down, what stops working when it goes dark, and what the fallback path is. If NetScaler fronts your VPN, the answer to "what breaks" is "remote work," and that is a business decision someone needs to have pre-authorized. A decision tree written during an incident is a decision tree written badly.

Treat any exposed appliance as already compromised, not merely vulnerable. With no IoCs published, you cannot prove a clean bill of health. Pull session tokens and rotate them, force re-authentication, and review the appliance's own logs for anomalies against your normal traffic shape. An RCE in the packet-processing path means anything the appliance held — VPN session tokens included — should be assumed read.

Appliances are the weakest link in most small-business stacks. They sit at the perimeter, they run vendor firmware you cannot inspect, they rarely have a staging twin, and they are often the one thing nobody wants to touch because everything depends on them. That last property is the problem. If a single box cannot be taken offline without stopping the company, that is an architecture finding, not an ops inconvenience.

Key takeaways

  • Two NetScaler ADC/Gateway RCE zero-days are under active exploitation with no CVE, no CVSS, and no Citrix advisory as of September 27
  • The Dutch NCSC warned organizations under TLP restrictions before September 25; Tenable has not independently reviewed that notice
  • Guidance is containment: shut down internet-exposed appliances or restrict them to trusted IPs, and never expose the management interface
  • Patches are expected early in the week of September 28 — exploitation typically rises once technical details publish
  • The EU Cyber Resilience Act's 24-hour exploited-vulnerability reporting began September 11, so expect more pre-patch, pre-CVE warnings
  • Operator move: for every internet-facing appliance, document who can shut it down, what breaks, and the fallback — before the next one of these

If one box going dark stops your business, that is a design problem you can fix. We build systems where the perimeter is replaceable, session state is rotatable, and "shut it off" is a runbook step instead of an outage. See how we build, or have us map your shutdown blast radius.

Sources: BleepingComputer, Tenable, European Commission.

  • #security
  • #netscaler
  • #zero-day
  • #citrix
  • #incident-response
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.