Two Citrix NetScaler Zero-Days Are Being Exploited Right Now

·
Listen to this article~4 min
Two Citrix NetScaler Zero-Days Are Being Exploited Right Now

Two unpatched zero-days in Citrix NetScaler ADC and Gateway are being actively exploited, allowing remote code execution. Citrix hasn't released a fix yet. Here's what you need to know.

### What's Happening with Citrix NetScaler? Security researchers at watchTowr dropped a bombshell on September 26: two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are actively being exploited in the wild. These flaws allow remote code execution (RCE), meaning an attacker could run malicious code on your appliance without ever touching it physically. That's about as bad as it gets for anyone running these systems. Citrix hasn't confirmed the vulnerabilities or released a fix yet. And some admins aren't waiting around. They're pulling their appliances offline entirely rather than risk a breach. It's a tough call, but when you're staring down active exploitation with no patch in sight, sometimes the safest move is to unplug. ### Why This Matters More Than You Think NetScaler ADC and Gateway sit at the edge of countless corporate networks. They handle load balancing, SSL offloading, and secure remote access. If an attacker gains RCE on one of these devices, they're essentially inside your network with a trusted foothold. From there, lateral movement is almost trivial. > "We've seen this movie before. Edge devices are the new front door for attackers, and they know it." — a security analyst familiar with the situation The fact that these are zero-days makes it worse. No patch means no easy fix. You can't just apply a vendor update and call it a day. You're forced to either mitigate manually, monitor like a hawk, or take the drastic step of going offline. ### What Should You Do Right Now? If you manage NetScaler appliances, here's a practical checklist: - **Isolate the appliance** if you can. Segment it from the rest of your network to limit blast radius. - **Check for indicators of compromise**. Look for unusual outbound connections, unexpected processes, or new admin accounts. - **Monitor logs aggressively**. Any strange authentication attempts or command execution should raise red flags. - **Prepare for a patch**. Citrix will likely release a fix soon. Have a maintenance window ready. - **Consider a temporary alternative**. Some teams are switching to VPN-only access or other remote solutions until the dust settles. It's not a perfect situation, but doing nothing is the worst option. ### The Bigger Picture: Why Zero-Days Keep Winning This isn't an isolated incident. Over the past few years, we've seen a steady stream of zero-days hitting edge devices from Citrix, Fortinet, Palo Alto, and others. Attackers love these targets because they're often internet-facing, hard to patch quickly, and provide deep access once compromised. For defenders, it's a constant game of whack-a-mole. You patch one hole, and another appears. That's why defense-in-depth matters more than ever. Assume your edge will be breached at some point. Plan accordingly. ### Final Thoughts The Citrix NetScaler zero-days are a serious reminder that even trusted enterprise gear can become a liability overnight. If you're running these appliances, don't wait for an official statement. Take action now. Isolate, monitor, and prepare to patch. Your network's security might depend on it. Stay safe out there.