TechRadar News.
Technology

Two Unpatched Citrix NetScaler Zero-Day Bugs Actively Exploited, Researchers Say

Two Unpatched Citrix NetScaler Zero-Day Bugs Actively Exploited, Researchers Say

On September 26, security researcher watchTowr cautioned that attackers are already exploiting two newly discovered flaws in Citrix NetScaler ADC and NetScaler Gateway appliances. Each defect enables unauthenticated remote code execution, giving malicious actors the ability to execute arbitrary commands on the compromised units without any prior foothold.

Because no fixes have been issued, the bugs are deemed zero‑days and impact the fundamental networking and application‑delivery capabilities of both hardware and virtual NetScaler appliances. watchTowr notes that these exploits have been spotted in active use, showing that threat actors have progressed from proof‑of‑concept stages to real‑world attacks against victim networks.

Citrix has so far neither acknowledged the vulnerabilities nor provided a schedule for a fix. Historically, the vendor has rolled out emergency patches within a few days to several weeks after a flaw becomes public. This lack of comment leaves NetScaler administrators—who rely on the devices for remote‑access protection and web‑traffic load balancing—without formal direction, amplifying the need for temporary defenses like network segmentation, tightened firewall policies, and diligent monitoring for unusual behavior.

Such zero‑day attacks are worrisome since NetScaler devices often sit at the edge of enterprise and cloud infrastructures, managing inbound traffic and VPN links. If compromised, attackers could establish a deep foothold inside the internal network, opening the door to data exfiltration, ransomware infection, or lateral spread. Because the two vulnerabilities affect both the ADC and the Gateway, they expose both standard web traffic and remote‑access channels.

Specialists recommend that firms running Citrix NetScaler keep an eye on vendor notices, implement any present mitigations, and look at short‑term fixes like turning off superfluous services or requiring multi‑factor authentication for remote connections. The wider security ecosystem is also scanning threat‑intel streams for IOCs tied to these exploits. As events unfold, Citrix will probably face growing demand to confirm the bugs and issue patches, while users balance the danger of ongoing exposure against their operational needs.

Source: feedburner
TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related