Two Unpatched Citrix NetScaler RCE Zero-Days Actively Exploited
Security firm watchTowr said on September 26 that two unpatched zero-day vulnerabilities allowing remote code execution in Citrix NetScaler ADC and NetScaler Gateway are being actively exploited in the wild. Citrix has not confirmed the flaws or released a fix, and some administrators have taken appliances offline.
- watchTowr disclosed the flaws on September 26
- Both vulnerabilities allow remote code execution
- Citrix has not confirmed the flaws or shipped a patch
- Some admins took appliances offline pending a fix
Read next
Security