Citrix NetScaler flaws under active attack
IPA warns of multiple actively exploited vulnerabilities in Citrix NetScaler ADC and Gateway allowing remote code execution or denial of service.
Japan's IPA has issued an alert regarding multiple vulnerabilities affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) appliances. Successful exploitation could allow a remote attacker to execute arbitrary code or cause a denial-of-service condition on affected devices. IPA confirms that exploitation of these flaws has already been observed in the wild, and warns that damage may spread further if organizations do not patch promptly.
The advisory urges administrators to apply vendor-provided updates immediately. It notes that NetScaler ADC and Gateway versions 12.1 and 13.0 have reached end-of-life and are no longer supported, meaning organizations still running these versions cannot receive fixes and should migrate to a supported, patched release. No specific CVE identifiers, threat actor attribution, or indicators of compromise were included in the source alert.
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20250827.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free