Two Citrix NetScaler Flaws Are Being Exploited Right Now
Michael Miller ·
Listen to this article~4 min
Citrix confirmed two critical NetScaler RCE vulnerabilities are being exploited in the wild. One affects every deployment on an impacted version — including default configs. Here's what to do now.
Citrix dropped a security bulletin on September 27, and it's not the kind of news you want to skim past. Two critical vulnerabilities in NetScaler ADC and NetScaler Gateway allow remote code execution — and attackers are already using them in the wild.
That means real people, real companies, real data. Not a theoretical risk on some researcher's whiteboard.
### What's Actually Going On
Here's the part that should make you sit up straight: one of these two flaws affects every deployment running an impacted version. Every single one. Even if you're running the default configuration — the setup you didn't customize, the one you assumed was safe — you're exposed.
Citrix released fixes for both vulnerabilities, plus six other flaws they found while digging around. So there's a path forward. But the window between "patch available" and "attackers knocking" is shrinking every year, and this is no exception.
### Why This One Hits Different
Remote code execution is about as bad as it gets. An attacker doesn't need physical access. They don't need to trick an employee into clicking something. They just need a vulnerable system reachable from the internet — and NetScaler boxes are often exactly that.
These appliances sit at the edge of corporate networks. They handle authentication, traffic routing, and access control. When one falls, the door swings wide open.
A day before Citrix published its bulletin, security firm watchTowr had already been tracking activity around these flaws. That timing matters. It suggests the security community was seeing signs of exploitation before the official word came down — which is rarely a good sign.
### What You Should Do Right Now
If you manage NetScaler infrastructure, don't wait for a maintenance window. Here's the short list:
- Check your current version against Citrix's advisory immediately
- Apply the available patches as soon as you can
- Review logs for any unusual outbound connections or unexpected process activity
- If you can't patch right away, restrict external access to the management interface
- Assume compromise if you were running an affected version unpatched — and investigate accordingly
### The Bigger Picture
Edge devices keep showing up in these stories because they're valuable targets. They're internet-facing, they often run older firmware, and they're frequently overlooked during routine security reviews.
Every organization has that one appliance someone inherited and nobody wants to touch. This is your reminder to go find it.
> "The patch exists. The exploit exists. The only question is which one reaches your system first."
That's not meant to scare you — it's meant to move you. The fix is available. The information is public. What happens next depends on how fast you act.
Citrix hasn't published details on who's behind the exploitation or how many organizations have been hit. But when a vendor confirms active attacks on a zero-day affecting default configurations, the safe assumption is that the number is growing.
Patch now. Check your logs. And if you've been putting off that NetScaler update, today's the day.