VORANT. Threat Intelligence Sign in Get the full feed

NetScaler ADC/Gateway flaws actively exploited

critical vulnerability

Critical vulnerabilities in NetScaler ADC and Gateway products are being actively exploited, enabling unauthenticated attackers to leak sensitive information or cause denial of service.

The Japan Information-technology Promotion Agency (IPA) issued an alert regarding multiple critical vulnerabilities affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) network appliance products. These vulnerabilities allow unauthenticated remote attackers to exfiltrate sensitive information or launch denial-of-service attacks against affected systems.

Active exploitation of these vulnerabilities has been confirmed in the wild, prompting urgent warnings from IPA that the impact may expand significantly. The agency emphasizes immediate patching is required to mitigate risk. NetScaler ADC and Gateway version 12.1 has reached end-of-life status and is no longer supported.

Citrix has released patched versions addressing these vulnerabilities. Organizations running affected NetScaler products should immediately upgrade to the latest versions provided by the vendor to prevent compromise. The IPA Security Center notes they cannot answer questions about individual systems and recommends contacting product vendors directly for environment-specific guidance.

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/alert20231023-2.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free