decrypted · 27 september 2026 · ransomware and cybercrime · vulnerabilities and patching · ai and llm security
Citrix's NetScaler has two zero-days and no patch yet
Citrix NetScaler customers spent the weekend doing something usually reserved for the worst day of the year: taking their own front door offline with no idea when it might reopen. On Friday a pre-notification attributed to the Dutch national cyber security centre, NCSC-NL, began circulating on a Citrix subreddit, describing unpatched remote code execution flaws in NetScaler ADC and Gateway and reportedly telling one managed service provider to shut appliances down immediately, no further detail given. By Saturday the security firm watchTowr said the intelligence was credible: two zero-day RCE vulnerabilities, found during forensic work on already-compromised customer environments, being exploited with no patch, no advisory and no CVE number issued. Citrix has confirmed nothing publicly. Reporting says it has told partners a fix is expected in the week starting 28 September.
What is confirmed, and what still is not
The two new flaws are distinct from CVE-2026-19490, an authentication bypass Citrix patched on 19 August. Beyond that, almost nothing is verified. The pre-notification itself was reportedly marked TLP AMBER+STRICT, a classification meant to keep it inside a small trusted circle; it did not stay there. No affected build ranges, no indicators of compromise, no proof-of-concept and no exploitation path have been published, so defenders cannot search their own logs for evidence either way. That has not stopped managed service providers and national agencies telling clients over the weekend to isolate or power down NetScaler appliances regardless, because the alternative, waiting for confirmation while an unauthenticated RCE sits on the internet-facing edge, is worse. It is an unusual position: acting on a credible tip with none of the technical detail that normally justifies the disruption.
The regulatory backdrop
The EU's Cyber Resilience Act introduced a new duty on 11 September: manufacturers must tell a national CSIRT and ENISA within 24 hours of learning that one of their products is being actively exploited, even before a fix exists. Whether that specific filing is what reached the Citrix subreddit is unconfirmed, but the dynamic on display this weekend, a CSIRT holding pre-patch knowledge that then surfaces publicly ahead of the vendor's own advisory, is exactly the scenario that duty creates. It is not a flaw in the law. Early warning before a fix is the point. But it does mean the UK, outside the regulation, is currently relying on Dutch disclosure and a security vendor's tweet rather than its own NCSC advisory, which had not appeared by the time of writing.
The design lesson for UK organisations
NetScaler joins F5 and Zyxel as the third edge or remote-access appliance in a month to end up in this position, and the pattern is the design flaw. These boxes are built to be reachable from anywhere and to hold the keys, sessions, certificates, authentication decisions, to everything behind them. Citrix's own incident guidance says the NetScaler Management Service should never be exposed to the public internet, yet the recurring lesson from every one of these incidents is that patch speed cannot be the only defence, because sometimes, as this weekend proved, there is no patch to apply for days. The organisations coping best right now are the ones that logged appliance activity somewhere the appliance itself cannot delete, segmented what the gateway can reach, and can survive taking it offline. That is a design decision made months before the incident, not a response to it.
Also this week
Researchers at Zenity Labs disclosed three flaws in Salesforce's Agentforce AI agents, dubbed SalesBleed, in which a poisoned Web-to-Lead form, the public lead-capture widget used on countless company websites, sat dormant until an employee asked an agent to process it, then hijacked the agent to exfiltrate CRM data through image tags or post phishing messages to internal Slack channels under the agent's own trusted identity. Salesforce fixed all three flaws by 19 August, following a 1 June report. The lesson holds regardless of the patch: an agent that inherits an employee's trust should not automatically inherit an anonymous form submission's instructions too.
Microsoft has named Storm-3168 what it calls the first documented agentic ransomware operation. Two compromised Azure service principals spent fifteen hours quietly mapping a tenant, then in a seven-minute burst deleted over one hundred storage accounts plus a Key Vault and a Function App, and tried to disable the backup and recovery locks that would have let the victim rebuild. The entry point was mundane: a client secret pasted into a public GitHub issue, later edited out, but still sitting in the issue's edit history. Deleting a comment does not delete a credential.
On 30 September the Information Commissioner's Office becomes the Information Commission, swapping a single statutory commissioner for a seven-member board under the Data (Use and Access) Act 2025. The regulator says every existing duty, breach-reporting timeline and enforcement power carries over unchanged, so nothing an organisation currently does around data protection needs to change on the day. Worth noting for the diary all the same, since the name on the next enforcement notice will be a new one.
Sources
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
- Citrix NetScaler Zero-Day RCE vulnerabilities: FAQ
- 'SalesBleed' Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
- Storm-3168: Agentic-driven cloud attacks using compromised service principals
- ICO to become Information Commission on 30 September 2026
If this raises questions about your own edge-device exposure, get in touch.
More like this
- F5's access gateway let attackers in without a password 23 september 2026
- One browser extension can take over the AI assistant built into your browser 19 september 2026
- The phone call that gets past your passkey 12 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.