• News/
  • https://www.bleepingcomputer.com/news/security/citrix-warns-of-new-netscaler-zero-days-exploited-in-attacks/

Citrix warns of new Netscaler zero-days exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 16, 2024
·
Updated

Citrix urged customers on Tuesday to immediately patch Netscaler ADC and Gateway appliances exposed online against two actively exploited zero-day vulnerabilities. The two zero-days (tracked as CVE-2023-6548 and CVE-2023-6549) impact the Netscaler management interface and expose unpatched Netscaler instances to remote code execution and denial-of-service attacks, respectively. However, to gain code execution, attackers must be logged in to low-privilege accounts on the targeted instance and need access to NSIP, CLIP, or SNIP with management interface access. Also, the appliances must be configured as a gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server to be vulnerable to DoS attacks. The company says that only customer-managed NetScaler appliances are impacted by the zero-days, while Citrix-managed cloud services or Citrix-managed Adaptive Authentication are not affected. The list of Netscaler product versions affected by these two zero-day vulnerabilities includes the following: According to data provided by threat monitoring platform Shadowserver, just over 1,500 Netscaler management interfaces are now exposed on the Internet. ​In a security advisory published today, Citrix urged all admins to immediately patch their Netscaler appliances against the two zero-days to block potential attacks. "Exploits of these CVEs on unmitigated appliances have been observed," the company warned. "Cloud Software Group strongly urges affected customers of Net...

Read full article

Affected Software

2 affected components
Citrix NetScaler ADC
Citrix NetScaler Gateway
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses newly discovered zero-day vulnerabilities in Citrix's NetScaler ADC and Gateway appliances that are currently being exploited.

2

What security implications are discussed in the article?

The article highlights the urgent need for customers to patch their Citrix appliances to prevent exploitation of two critical vulnerabilities.

3

What vulnerabilities are mentioned in the article?

The article specifically mentions CVE-2023-6548 and CVE-2023-6549 as the zero-day vulnerabilities affecting the Citrix products.

4

Which products are impacted by the vulnerabilities?

The affected products are Citrix NetScaler ADC and Citrix NetScaler Gateway.

5

What action is recommended for Citrix customers?

Citrix urges customers to immediately apply patches to their NetScaler ADC and Gateway appliances to mitigate the risks posed by these vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203