NetScaler ADC RCE flaw actively exploited
IPA warns that a remote code execution vulnerability in Citrix NetScaler ADC and Gateway is being actively exploited and urges immediate patching.
Japan's IPA (Information-technology Promotion Agency) issued an alert regarding an arbitrary code execution vulnerability affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway), network appliance products widely used for application delivery and remote access. The vulnerability allows an unauthenticated remote attacker to execute arbitrary code on affected devices.
The advisory confirms that exploitation of this vulnerability has already been observed in the wild, with IPA warning that damage may spread further if organizations do not act quickly. Users are urged to update to the vendor-supplied fixed versions immediately. IPA also notes that NetScaler ADC and Gateway version 12.1 has reached end-of-life and is no longer supported, meaning organizations still running that version should migrate to a current, patched release rather than expect a fix.
Given the appliance's internet-facing role and history of prior Citrix ADC/Gateway vulnerabilities being leveraged for initial access by threat actors, prompt patching is recommended for all deployments.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/alert20230719.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free