Two Unpatched Citrix NetScaler RCE Zero-Days Reportedly Exploited

· Original article ↗

Summary

watchTowr reports active exploitation of two unpatched NetScaler ADC and Gateway RCE flaws. Citrix has not confirmed them or released fixes, workarounds, or indicators of compromise; administrators are isolating or shutting down appliances.

Key points

  • watchTowr says two previously undisclosed, unpatched remote code execution vulnerabilities in NetScaler ADC and Gateway are being exploited in the wild.
  • The firm says the exploitation was discovered during forensic investigations, but has not published evidence or identified affected organizations.
  • Citrix had not confirmed the flaws or released a patch, workaround, or indicators of compromise as of the article’s publication.
  • Some administrators reportedly took appliances offline; Citrix’s existing guidance for suspected compromise recommends preserving evidence, isolating appliances, and rotating credentials and secrets.
  • Installing a future fix may not establish whether an attacker gained access before patching; administrators are also advised to keep management interfaces off the public internet.
  • Citrix has not said whether NetScaler 13.1, which reached End of Maintenance on September 15, will receive a fix.

Article Details

Event Type
Reported active exploitation of two unpatched zero-day remote code execution vulnerabilities
Impact
The flaws could allow remote code execution on affected NetScaler appliances. No victims or confirmed compromises were disclosed.

CVE

Vendors

Products

Related Articles