Two Unpatched Citrix NetScaler Zero-Day RCE Flaws Actively Exploited, Urging Immediate Patch
Citrix confirmed that two critical remote-code-execution vulnerabilities in NetScaler ADC and Gateway are being exploited in the wild, and patches have been released.
Written and published by the Wepro Technology team
The Hacker News reported on 27 September that Citrix has confirmed active exploitation of two critical zero‑day vulnerabilities affecting its NetScaler ADC and NetScaler Gateway appliances.
Both flaws allow unauthenticated remote code execution; one of them can be triggered on any deployment of the affected versions, even when the device is left in its default configuration, giving attackers full control of the underlying server.
Citrix issued patches for the two zero‑days on the same day, alongside fixes for six additional security issues, and urged customers to apply the updates immediately to stop the ongoing attacks.
Australian organisations, including government agencies and businesses in Darwin, should treat these patches as high priority, as many rely on Citrix NetScaler for VPN and application delivery services that are integral to remote‑work environments and compliance with the Australian Signals Directorate’s Essential Eight.
For IT professionals and students looking to deepen their understanding of network security and vulnerability management, Wepro Technology in Darwin offers courses such as Security+ and advanced networking training that cover best practices for patch management and incident response.
Stay ahead in IT
Join 200+ Australian IT professionals getting weekly insights delivered to their inbox.
- Weekly IT news & insights
- New course announcements
- Free quiz updates
Your email
No spam, ever · Unsubscribe anytime