# NetScaler ADC/Gateway flaws actively exploited

Published: 2023-10-22 · Severity: critical
Canonical: https://vorant.io/reports/43a2b084-68b1-4160-927e-27bc05b30477/netscaler-adc-gateway-flaws-actively-exploited

> Critical vulnerabilities in NetScaler ADC and Gateway products are being actively exploited, enabling unauthenticated attackers to leak sensitive information or cause denial of service.

The Japan Information-technology Promotion Agency (IPA) issued an alert regarding multiple critical vulnerabilities affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) network appliance products. These vulnerabilities allow unauthenticated remote attackers to exfiltrate sensitive information or launch denial-of-service attacks against affected systems.

Active exploitation of these vulnerabilities has been confirmed in the wild, prompting urgent warnings from IPA that the impact may expand significantly. The agency emphasizes immediate patching is required to mitigate risk. NetScaler ADC and Gateway version 12.1 has reached end-of-life status and is no longer supported.

Citrix has released patched versions addressing these vulnerabilities. Organizations running affected NetScaler products should immediately upgrade to the latest versions provided by the vendor to prevent compromise. The IPA Security Center notes they cannot answer questions about individual systems and recommends contacting product vendors directly for environment-specific guidance.

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/alert20231023-2.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/43a2b084-68b1-4160-927e-27bc05b30477/netscaler-adc-gateway-flaws-actively-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
