Citrix confirmed active exploitation of two critical remote code execution flaws in NetScaler ADC and NetScaler Gateway products on September 27. The vendor released patches for both vulnerabilities along with fixes for six additional flaws discovered during the same security review.

One of the two zero-day flaws affects all deployments running vulnerable versions, even those using default configurations. This broad exposure makes the vulnerability particularly dangerous for organizations that have not yet applied patches. No configuration changes or workarounds exist to mitigate the risk without patching.

Security firm watchTowr disclosed the vulnerabilities. Their research preceded Citrix's official acknowledgment by one day, suggesting the company discovered active exploitation in production environments before public disclosure became necessary.

Citrix NetScaler ADC and NetScaler Gateway serve as critical load balancers and remote access gateways for thousands of enterprises globally. Both products sit at network perimeters and handle authentication, traffic routing, and VPN connectivity. Compromise of these appliances grants attackers direct access to internal networks, user credentials, and sensitive business systems.

The active exploitation status elevates threat severity beyond typical vulnerability announcements. Attackers already deploying these exploits can compromise unpatched NetScaler instances without requiring user interaction or specialized network positioning. Reconnaissance tools can identify exposed NetScaler instances at internet-facing boundaries, making detection and targeting trivial for organized threat actors.

Organizations running NetScaler ADC or NetScaler Gateway face immediate operational risk. Network defenders must prioritize patching these systems ahead of other infrastructure updates due to their privileged position in network architecture. Delaying patches extends exposure windows during which adversaries can establish persistence, harvest credentials, and move laterally into corporate networks.

The default configuration vulnerability presents particular urgency. Standard deployments require no attacker customization or environmental knowledge to exploit successfully. Organizations believing their NetScaler instances are adequately hardened through security controls may discover this assumption false if they run unpatched versions.

Citrix customers should immediately apply the released security updates to all NetScaler ADC and NetScaler Gateway installations. Organizations should verify patch deployment across all instances, including appliances deployed in remote offices, cloud environments, or third-party managed services. Testing patches in non-production environments before full rollout remains prudent, but this process should complete rapidly given the active threat.

Organizations unable to patch immediately due to change control restrictions or testing requirements should implement network segmentation to limit access to NetScaler management interfaces. Disabling unnecessary services and restricting administrative access to known source IP addresses provides temporary protective measures. These controls do not eliminate risk from network-accessible exploitation paths but reduce potential attack surface.

Threat intelligence teams should monitor for exploitation attempts targeting these vulnerabilities through network telemetry and endpoint detection tools. NetScaler logs may contain evidence of exploitation attempts, though compromised instances could contain manipulated or deleted logs. Organizations should preserve NetScaler logs offline for forensic review if breach investigation becomes necessary.

The dual zero-day disclosure demonstrates the value of coordinated vulnerability research and responsible disclosure practices. watchTowr's findings prompted rapid vendor response, allowing customers a reasonable window to patch before widespread public exploitation becomes routine. Organizations that apply these patches immediately gain protection unavailable to late adopters.