# Citrix NetScaler flaws under active attack

Published: 2025-08-26 · Severity: high · Sectors: infrastructure, technology
Canonical: https://vorant.io/reports/2a03b778-fd41-5709-a0bf-adba3aa9450a/citrix-netscaler-flaws-under-active-attack

> IPA warns of multiple actively exploited vulnerabilities in Citrix NetScaler ADC and Gateway allowing remote code execution or denial of service.

Japan's IPA has issued an alert regarding multiple vulnerabilities affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) appliances. Successful exploitation could allow a remote attacker to execute arbitrary code or cause a denial-of-service condition on affected devices. IPA confirms that exploitation of these flaws has already been observed in the wild, and warns that damage may spread further if organizations do not patch promptly.

The advisory urges administrators to apply vendor-provided updates immediately. It notes that NetScaler ADC and Gateway versions 12.1 and 13.0 have reached end-of-life and are no longer supported, meaning organizations still running these versions cannot receive fixes and should migrate to a supported, patched release. No specific CVE identifiers, threat actor attribution, or indicators of compromise were included in the source alert.

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20250827.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2a03b778-fd41-5709-a0bf-adba3aa9450a/citrix-netscaler-flaws-under-active-attack.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
