VORANT. Threat Intelligence Sign in Get the full feed

NetScaler ADC zero-day exploited in wild

critical vulnerability

Multiple vulnerabilities in NetScaler ADC and Gateway are under active exploitation, enabling remote code execution and denial of service — immediate patching required.

Japan's IPA has issued an urgent security alert for multiple vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) network appliances. The flaws allow remote attackers to execute arbitrary code or cause denial-of-service conditions.

Active exploitation has been observed in the wild, prompting IPA to warn that damage may expand and urge organizations to apply updates immediately. The vendor has released patched versions to address the vulnerabilities. IPA notes that NetScaler ADC and Gateway versions 12.1 and 13.0 have reached end-of-life and are no longer supported.

Organizations running affected NetScaler products should prioritize patching to the latest versions provided by the vendor. Given the confirmed in-the-wild exploitation and the criticality of these network appliances in enterprise environments, delayed remediation poses significant risk.

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20250827.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free