Two Unpatched Citrix NetScaler RCE Zero-Days Reportedly Exploited

Summary
watchTowr reports active exploitation of two unpatched NetScaler ADC and Gateway RCE flaws. Citrix has not confirmed them or released fixes, workarounds, or indicators of compromise; administrators are isolating or shutting down appliances.
Key points
- watchTowr says two previously undisclosed, unpatched remote code execution vulnerabilities in NetScaler ADC and Gateway are being exploited in the wild.
- The firm says the exploitation was discovered during forensic investigations, but has not published evidence or identified affected organizations.
- Citrix had not confirmed the flaws or released a patch, workaround, or indicators of compromise as of the article’s publication.
- Some administrators reportedly took appliances offline; Citrix’s existing guidance for suspected compromise recommends preserving evidence, isolating appliances, and rotating credentials and secrets.
- Installing a future fix may not establish whether an attacker gained access before patching; administrators are also advised to keep management interfaces off the public internet.
- Citrix has not said whether NetScaler 13.1, which reached End of Maintenance on September 15, will receive a fix.
Article Details
- Event Type
- Reported active exploitation of two unpatched zero-day remote code execution vulnerabilities
- Impact
- The flaws could allow remote code execution on affected NetScaler appliances. No victims or confirmed compromises were disclosed.
CVE
Vendors
Products
NetScaler ADCTwo newly uncovered, unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited in the wild, according to watchTowr.NetScaler GatewayTwo newly uncovered, unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited in the wild, according to watchTowr.