Two Unpatched Citrix NetScaler Zero-Day Bugs Actively Exploited, Researchers Report
On September 26, security research outfit watchTowr cautioned that attackers are already exploiting two newly discovered flaws in Citrix NetScaler ADC and NetScaler Gateway appliances. Each vulnerability enables unauthenticated remote code execution, letting threat actors execute arbitrary commands on the compromised devices without any prior foothold.
Because no patches exist, these issues are classified as zero‑days and impact the fundamental networking and application‑delivery capabilities of both hardware and virtual NetScaler appliances. watchTowr notes that the exploits have already been seen in operational environments, showing that adversaries have progressed from proof‑of‑concept stages to active use against victim networks.
Citrix has not publicly acknowledged the bugs nor provided a schedule for a fix. Historically, the firm has rolled out emergency patches within days to a few weeks after a vulnerability becomes known. This lack of comment leaves NetScaler administrators—who rely on the devices for remote‑access protection and web‑traffic load balancing—without official direction, amplifying the need for temporary defenses like network segmentation, tight firewall policies, and vigilant monitoring for unusual behavior.
Such zero‑day attacks are worrisome given that NetScaler devices occupy the edge of numerous enterprise and cloud infrastructures, managing inbound traffic and VPN links. If compromised, attackers can establish a deep foothold inside the internal network, opening the door to data exfiltration, ransomware infection, or lateral propagation. Because the two vulnerabilities affect both the ADC and the Gateway, they expose both standard web traffic and remote‑access channels.
Specialists recommend that firms deploying Citrix NetScaler keep an eye on vendor bulletins, implement any interim mitigations, and possibly adopt short‑term fixes like turning off non‑essential services or mandating multi‑factor authentication for remote logins. The wider security community is likewise tracking threat‑intel sources for IOCs tied to these exploits. As events unfold, Citrix will likely face growing demand to confirm the flaws and issue patches, while customers balance the danger of ongoing exposure against practical operational limits.
Comments (0)
Be the first to comment.
Join the discussion