Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Summary
Two zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are being actively exploited in the wild, according to security firm watchTowr. These vulnerabilities allow for remote code execution, and Citrix has not yet confirmed the flaws or released a fix. Some administrators are reportedly taking their appliances offline to mitigate the risk.
IFF Assessment
The active exploitation of unpatched zero-day vulnerabilities in critical network infrastructure poses a significant threat to organizations, enabling attackers to gain unauthorized access and execute malicious code.
Severity
These are unpatched RCE zero-days in critical network appliances, implying high impact (Confidentiality, Integrity, Availability) and exploitability without prior authentication or user interaction. A CVSS score of 9.0 reflects critical severity.
Defender Context
Defenders should be aware of these active exploits targeting Citrix NetScaler appliances. Until patches are available, implementing compensating controls, such as network segmentation, strict access controls, and enhanced monitoring for unusual activity on affected devices, is crucial. Organizations should prioritize a rapid response once official mitigations or patches are released by Citrix.