Wire Observer.
Technology

Active Exploitation Reported for Two Unpatched Citrix NetScaler Zero-Day Flaws

Active Exploitation Reported for Two Unpatched Citrix NetScaler Zero-Day Flaws

Security research firm watchTowr warned on September 26 that two previously unknown vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are being leveraged by attackers in real‑world campaigns. Both flaws permit unauthenticated remote code execution, allowing threat actors to run arbitrary commands on affected devices without prior access.

The vulnerabilities, classified as zero‑days because no patches have been released, affect the core networking and application‑delivery functions of NetScaler hardware and virtual appliances. According to watchTowr, the exploits are already observed in the wild, indicating that malicious actors have moved beyond proof‑of‑concept testing to active deployment against target networks.

Citrix has not yet confirmed the existence of the flaws nor announced a remediation timeline. In past incidents, the company has typically issued emergency patches within days to weeks after a vulnerability is disclosed. The current silence leaves administrators of NetScaler deployments—often used to secure remote access and load‑balance web traffic—without official guidance, heightening the urgency for interim mitigation measures such as network segmentation, strict firewall rules, and rigorous monitoring for anomalous activity.

Zero‑day exploits of this nature are especially concerning because NetScaler appliances sit at the perimeter of many enterprise and cloud environments, handling inbound traffic and VPN connections. A successful breach can grant attackers a foothold deep within an organization’s internal network, potentially facilitating data theft, ransomware deployment, or lateral movement. The dual‑vector nature of the flaws—affecting both the ADC and the Gateway—means that both traditional web traffic and remote‑access pathways are exposed.

Experts advise organizations using Citrix NetScaler to review vendor advisories regularly, apply any available mitigations, and consider temporary workarounds such as disabling unnecessary services or enforcing multi‑factor authentication for remote access. The broader security community is also monitoring threat‑intel feeds for indicators of compromise linked to the reported exploits. As the situation evolves, pressure will likely mount on Citrix to validate the vulnerabilities and deliver patches, while customers weigh the risk of continued exposure against operational constraints.

Source: feedburner
Christina Kyriasoglou — Bloomberg (Berlin, Germany)

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related