Critical Citrix NetScaler RCE Flaws Exploited in Wild
Two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway are under active exploitation. Immediate patching is required to prevent remote code execution.
TL;DR
- Citrix confirms two critical RCE vulnerabilities in NetScaler ADC and Gateway are being actively exploited.
- One flaw impacts all deployments, even with default configurations.
- Patches are now available for both zero-days and six additional issues.
- Organizations should update immediately to avoid compromise.
- Security firm watchTowr first flagged the vulnerabilities.
Citrix has confirmed that two critical remote code execution vulnerabilities in its NetScaler ADC and Gateway products are being actively exploited in the wild. The flaws, which received patches on September 27, pose a significant risk to organizations running affected versions.
One of the vulnerabilities affects all deployments of impacted versions, regardless of configuration, making it especially dangerous. Organizations using Citrix NetScaler products should prioritize applying the newly released updates to mitigate potential breaches.
The warning follows reports from security researchers at watchTowr, who identified the vulnerabilities and notified Citrix prior to public disclosure. In total, Citrix addressed eight security issues in its latest advisory, underscoring the importance of proactive vulnerability management.
Vulnerability Details
- Two zero-day RCE vulnerabilities (CVE identifiers pending) were found in Citrix NetScaler ADC and Gateway.
- One vulnerability impacts every deployment on affected versions, including default configurations.
- Both flaws allow unauthenticated attackers to execute arbitrary code remotely.
- Six additional vulnerabilities were also patched in the same advisory.
- Exploitation was confirmed by Citrix following reports from security firm watchTowr.
Recommended Actions
- Immediately apply the official patches released by Citrix on September 27.
- Review network logs for signs of unauthorized access or suspicious activity targeting NetScaler instances.
- Ensure all systems are updated, especially those exposed to the internet or public-facing.
- Consider engaging third-party security experts for audit if NetScaler has been exposed long-term.
- Subscribe to Citrix security advisories for future updates and threat intelligence.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.