Critical NetScaler Zero-Days Exploited: What You Need to Know

Two critical remote code execution zero-days in Citrix NetScaler appliances are actively exploited. Immediate patching is essential to prevent compromise and system disruption.

Critical NetScaler Zero-Days Exploited: What You Need to Know
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What are the NetScaler Zero-Day Vulnerabilities?

Two severe zero-day vulnerabilities have been discovered and patched in Citrix NetScaler ADC and Gateway appliances. Both allow remote code execution (RCE) by unauthenticated attackers, making them highly dangerous. The first flaw stems from improper input validation, which permits execution of arbitrary commands remotely. The second is a buffer overflow and memory corruption vulnerability that could also cause denial of service (DoS).

Given their critical nature—with severity scores of 9.5/10—these vulnerabilities can be exploited from outside an organization's network without needing any prior authentication.

Why are NetScaler Appliances Especially Vulnerable?

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws  Globally
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

NetScaler devices are commonly used to provide remote access to internal corporate resources. They sit at the network perimeter and are often exposed directly to the internet, making them prime targets for attackers. Because they grant privileged access into enterprise environments, a successful exploit can lead directly to internal network compromise.

Additionally, network appliances like NetScaler typically undergo less rigorous monitoring compared to endpoints such as servers or desktops, creating a blind spot for attackers to exploit. This makes zero-day bugs in these devices particularly valuable to threat actors—including both cybercriminal gangs and nation-state groups aiming for stealthy, high-impact intrusions.

What Has Been Observed in the Wild?

Exploitation of these vulnerabilities is confirmed to be occurring in active attacks. Several IT teams and security agencies have issued urgent advisories, urging immediate shutdown or patching of vulnerable NetScaler appliances. The US Cybersecurity and Infrastructure Security Agency (CISA) added these flaws to their known exploited vulnerabilities catalog, mandating patching within a very short timeframe.

Reports indicate attackers are rapidly leveraging these zero-days to gain remote access and potentially move laterally inside networks to deploy ransomware or steal credentials, emphasizing the severity and urgency of remediation.

What Should Organizations Do Right Now?

Citrix Releases Emergency NetScaler Patches After Two Zero-Days Exploited  In Attacks
Citrix Releases Emergency NetScaler Patches After Two Zero-Days Exploited In Attacks
  1. Immediately apply the official Citrix patches for NetScaler ADC and Gateway versions prior to 14.1-73.37 and 13.1-64.23, including all FIPS and NDcPP builds.
  2. If patching is not feasible immediately, consider isolating or shutting down exposed NetScaler appliances until secure updates can be applied.
  3. Increase monitoring and logging on all NetScaler devices to detect suspicious activity or signs of compromise.
  4. Review network segmentation and access controls to limit potential attacker lateral movement if a device is compromised.
  5. Regularly check authoritative vulnerability databases and advisories for updates or mitigations.

Practical Security Takeaway

The exploitation of critical zero-days in networking appliances like NetScaler highlights the need for fast vulnerability management and comprehensive exposure reduction strategies. Organizations dependent on these appliances should prioritize patching and enhance visibility into these systems since attackers actively target these high-value entry points. Neglecting such infrastructure risks severe business disruption and data breaches, emphasizing that perimeter devices require as much scrutiny and rapid updating as endpoints.

React to this story

Related Posts