Inside the Citrix NetScaler Zero Day Saga
This case is yet another reminder just how important vendor communication is in such incidents and how much uncertainty can hamper security.

This case is yet another reminder just how important vendor communication is in such incidents and how much uncertainty can hamper security.
September 29, 2026 | 1 min read

When indications of exploit activity against an unknown vulnerability in Citrix NetScaler ADC and Gateway appliances late last week, researchers at watchTowr were among the first to speak up publicly about what was going on. They had information from national CERT authorities about the exploits, and recommended that customers take their appliances offline until fixes were ready.
It was a long weekend as customers and security teams waited for any sort of communication from Citrix, which didn't come until an advisory and patches were released Sunday afternoon. This case is yet another reminder just how important vendor communication is in such incidents and how much uncertainty can hamper security.
Ben Harris of watchTowr joins Dennis Fisher to walk through the Citrix NetScaler zero days that emerged over the weekend, from first detection of exploitation to reporting to finally some patches and why vendor communication is so vital in these cases.
September 29, 2026 | 1 min read
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.