Attackers Exploit Unpatched Citrix NetScaler Flaws for Remote Code Execution

Security researchers at watchTowr reported on September 26 that attackers are exploiting two previously unknown flaws in Citrix NetScaler ADC and Gateway. The vulnerabilities permit remote code execution, and Citrix has not yet acknowledged them or released patches. Some administrators have disconnected affected appliances while awaiting a fix.
On September 26, watchTowr researchers reported that two previously unidentified flaws in Citrix NetScaler ADC and Gateway are being exploited in attacks. These vulnerabilities permit remote code execution.
No acknowledgment or patch has come from Citrix. Some administrators have taken affected appliances offline until a remedy is available, leaving the situation unresolved.
Organizations using Citrix NetScaler ADC and Gateway could face disruption, along with administrators and people who depend on services behind those appliances. If exploitation continues without patches, systems may be at greater risk, and taking devices offline could interrupt access. The episode may also heighten scrutiny of how quickly vendors address serious security flaws.