Two unpatched Citrix NetScaler zero-days enabling remote code execution are reportedly under active attack, with no vendor patch.
Tenable's Research Special Operations team published an FAQ on two reported Citrix NetScaler zero-days that can enable remote code execution. As of September 27, 2026, neither flaw has a CVE, and Citrix has not issued an advisory or patches. watchTowr and Kevin Beaumont say the bugs are used in active attacks, though widespread scale is unconfirmed. The issues are unrelated to patched CVE-2026-19490 and CVE-2026-19489; reports began with a September 25 Reddit post citing a restricted NCSC-NL pre-notification.
Two unpatched NetScaler zero-days reportedly allow remote code execution.
Reports cite an NCSC-NL TLP:AMBER+STRICT pre-notification, not a Citrix advisory.
watchTowr and Kevin Beaumont say attacks are active and no patch exists.
Flaws are unrelated to patched CVE-2026-19490 and CVE-2026-19489.
Citrix had published no formal advisory as of September 27, 2026.
Full article1,081 words · extracted from tenable.com · click to collapse
There are reportedly two unpatched zero-day Citrix NetScaler vulnerabilities capable of enabling remote code execution that have been actively exploited in the wild, with no patches available at this time.
Key takeaways
Reports indicate that there are two critical zero-day vulnerabilities in Citrix NetScaler.
The reports originate from a pre-notification sent out ahead of public disclosure, so there are currently no specific details about these flaws and no patches available.
This post will be updated as new information becomes available.
Background
Tenable's Research Special Operations (RSO) team has compiled this blog to answer Frequently Asked Questions (FAQ) regarding two reported zero-day vulnerabilities in Citrix NetScaler that sources say were actively exploited in the wild. The following FAQ is based on limited public information. This post will be updated with additional details once more information becomes public over the next week.
FAQ
What is the source of the NetScaler vulnerabilities?
On September 25, 2026, reports surfaced through a reddit post on r/Citrix regarding advice to shut down “Netscalers.” This included a report from a user that said this information came from the “Dutch national cyber security center” and further details included a note about two zero-day vulnerabilities.
On September 26, 2026, additional reports confirming the existence of these flaws became public, including social posts from researchers at watchTowr on X, as well as Kevin Beaumont on Mastodon.
What is the context surrounding the National Cyber Security Centre (NCSC-NL) alert?
The Reddit post on r/Citrix cited details from an NCSC-NL pre-notification that had not yet been made public. Community members in that thread said the pre-notification was distributed under Traffic Light Protocol (TLP):AMBER+STRICT restrictions. Tenable's RSO has not independently obtained or reviewed the contents of this notification.
Has Citrix confirmed the presence of zero-day vulnerabilities?
As of September 27, a formal security advisory from Citrix has not been published.
What are these zero-day vulnerabilities?
Based on public reporting as of September 27, there are reportedly two zero-day vulnerabilities in Citrix NetScaler devices that can lead to remote code execution (RCE):
CVE
Description
CVSSv3
Not Assigned
Citrix NetScaler RCE
N/A
Not Assigned
Citrix NetScaler RCE
N/A
watchTowr confirmed details for both on September 26, 2026:
We have been made aware of further info, which we are sharing. We had no idea Citrix sysadmins were like GTA6 fans - so friendly 🤗
Please, direct further questions to Citrix. We are not Citrix PSIRT (despite it occasionally looking that way).
Are these zero-day vulnerabilities related to CVE-2026-19490 and CVE-2026-19489?
No. Neither CVE-2026-19490 nor CVE-2026-19489 appears to be related. Both are previously disclosed vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway for which patches are available. CVE-2026-19490 was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026.
Reports say these vulnerabilities were exploited. How widespread are the attacks?
Based on public reporting, it has not been determined whether exploitation has reached widespread scale. On September 26, Kevin Beaumont stated: “The Netscaler zero day thing is real, being used in active attacks. No patch yet, if sensitive to Netscaler vulns switch it off.”
How many Citrix NetScaler vulnerabilities have been exploited in the wild in the past?
Citrix NetScaler devices have historically been a popular target for attackers. Including CVE-2026-19490, as of September 27, 2026, there were 13 NetScaler-related entries in CISA's KEV catalog and 24 entries for Citrix products overall. The RSO team has covered several notable incidents:
Which threat actors are exploiting these vulnerabilities?
No details about threat actors have been made public at this time. However, based on our research, roughly two-thirds of threat actor activity targeting Citrix NetScaler over the last seven years involved advanced persistent threat (APT) groups, while one-third involved ransomware groups and their affiliates.
Is there a proof-of-concept (PoC) available for these vulnerabilities?
As of September 27, 2026, there are no public proofs-of-concept (PoCs) for these vulnerabilities.
Are patches or mitigations available?
As of September 27, a formal security advisory from Citrix has not been published as of this writing and no patches are currently available. However, public reporting indicates that Citrix plans to release patches early in the week of September 28, 2026.
Are there any indicators of compromise for these vulnerabilities?
There are currently no indicators of compromise (IoCs) publicly available.
Has Tenable Research classified these vulnerabilities as part of Vulnerability Watch?
No. Tenable Research will classify the reported Citrix NetScaler zero-day vulnerabilities as part of Vulnerability Watch once CVE IDs have been assigned.
Has Tenable released any product coverage for these vulnerabilities?
No. Once CVE IDs are assigned and patches are released, this post will be updated with plugin links. As always, customers can expect that forthcoming plugins will appear in the Plugins Pipeline as they are released.
Unauthenticated path traversal RCE in Citrix ADC, Gateway, and SD-WAN WANOP
CVE-2019-19781 is a path-traversal flaw (classified CWE-22, though CISA's description calls it unspecified) in Citrix ADC (formerly NetScaler ADC), Citrix Gateway, and Citrix SD-WAN WANOP appliances that lets an unauthenticated remote attacker traverse directories via crafted requests and execute arbitrary commands on the appliance, typically with root privileges. It is triggered by sending specially crafted directory-traversal requests (crafted URLs/requests to the appliance's management or VPN endpoints), which lets the attacker write files and run commands with no credentials. Successful exploitation yields arbitrary code execution on the appliance, enabling theft of VPN/ADC credentials, lateral movement into the corporate network, and installation of persistent backdoors. Any organization running affected ADC, Gateway, or SD-WAN WANOP firmware is affected, with internet-facing gateways used for remote access at the highest risk. Exploitation is confirmed in the wild: the vulnerability is on CISA's KEV (added 2021-11-03) with known ransomware use, EPSS assigns near-certain (100.0%) probability of exploitation within 30 days, and no public PoC is listed despite confirmed abuse.
Do: Upgrade Citrix ADC, Gateway, and SD-WAN WANOP appliances to the fixed firmware builds listed in Citrix advisory CTX267020; if patching cannot be done immediately, apply Citrix's published interim mitigation and restrict internet exposure to the appliance. Because exploitation grants root code execution and persistence, after patching hunt for indicators of compromise (unexpected nsroot account, modified system files, crontab/scheduled entries), kill all active and inactive sessions, and rotate appliance and VPN credentials. Prioritize internet-facing gateways and comply with CISA's required action to apply vendor updates.
9.8
100%
KEV ransomware
Citrix Application Delivery Controller (ADC) Supported ADC firmware lines in effect at disclosure (10.5, 11.0, 11.1, 12.0, 12.1, 13.0) prior to patched builds, per Citrix advisory CTX267020; exact builds n
Citrix Gateway Supported Gateway firmware lines (sharing the ADC codebase, same affected releases 10.5-13.0) prior to patched builds, per Citrix advisory; exact builds not spe
Citrix SD-WAN WANOP Appliance Affected appliance models (4000, 4100, 5000, 5100) running pre-patch firmware in the 10.2.1-11.4.1 range, per Citrix advisory; exact builds not specified in the
massroughly 80,000-100,000+ internet-exposed Citrix ADC/Gateway appliances at the time of disclosure, with a far larger total installed base (including…
Unauthenticated Authorization Bypass in Citrix ADC, Gateway, and SD-WAN WANOP
CVE-2020-8193 is an improper access control flaw (CWE-284/CWE-287) in Citrix ADC, Citrix Gateway, and Citrix SD-WAN WAN-OP appliances that lets an unauthenticated remote attacker reach certain URL endpoints that should require authentication. An attacker triggers it simply by sending crafted HTTP requests over the network, with no credentials or user interaction required. The direct impact is limited (CVSS 3.1 rates it 6.5 with low confidentiality and integrity impact), but access to protected endpoints can expose sensitive information and is commonly chained with other Citrix flaws; a public proof of concept for local file inclusion against Citrix ADC/NetScaler exists. Anyone running Citrix ADC or Gateway builds before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, or 10.5-70.18, or SD-WAN WAN-OP builds before 11.1.1a, 11.0.3d, or 10.2.7 is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog in November 2021 and was named in the NSA's list of the top 25 flaws actively exploited by Chinese state-sponsored hackers, with an EPSS probability of exploitation of 88.4%.
Do: Upgrade Citrix ADC and Citrix Gateway to at least 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, or 10.5-70.18, and SD-WAN WAN-OP to at least 11.1.1a, 11.0.3d, or 10.2.7, per Citrix's instructions. Prioritize internet-facing ADC/Gateway appliances (VPN gateways and load balancers), since the flaw is reachable without credentials, and review appliance logs for unauthenticated access to protected endpoints. This CVE is on the CISA KEV list, so federal and KEV-committed defenders are required to apply the vendor updates.
Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway
CVE-2023-3519 is a critical (CVSS 9.8) unauthenticated remote code execution flaw caused by improper code-injection handling (CWE-94) in Citrix NetScaler ADC and NetScaler Gateway. A remote attacker with no credentials can trigger it by sending crafted requests to an appliance configured as a Gateway (VPN/ICA proxy/RDP proxy) or AAA authentication virtual server, gaining arbitrary code execution on the appliance. Exploitation typically yields a foothold behind the VPN edge — access to internal networks, credential theft, and follow-on activity such as espionage or ransomware deployment. Any organization running unpatched NetScaler ADC/Gateway appliances, especially internet-facing remote-access endpoints, is affected; NetScaler is one of the most widely deployed enterprise VPN/ADC platforms. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-07-19 with known ransomware use, EPSS estimates a 99.7% exploitation probability, and researchers have linked activity to China-nexus espionage (Silk Typhoon) and ransomware operations.
Do: Immediately upgrade internet-facing NetScaler ADC/Gateway appliances to the fixed builds in Citrix's advisory (14.1-8.50+, 13.1-49.13+, 13.0-82.45+, 12.1-55.300+, including FIPS/NDcPP equivalents) — per CISA KEV, apply these mitigations or discontinue use if patching is unavailable. Confirm whether each appliance is configured as a Gateway or AAA virtual server (only those are affected), and hunt for compromise — unexpected configuration changes, unfamiliar accounts, webshells, or anomalous VPN sessions — rotating credentials on any suspected compromise.
Info-Disclosure Buffer Overflow (CitrixBleed) in Citrix NetScaler ADC/Gateway
Citrix NetScaler ADC and NetScaler Gateway appliances contain a buffer overflow (CWE-119) that leaks sensitive information from device memory when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. A remote attacker who can reach such a configuration can trigger the overflow and read memory contents, harvesting sensitive data such as session tokens (a technique that enables session hijacking which can bypass multi-factor authentication). Any organization running an affected NetScaler ADC or Gateway appliance in these configurations is exposed, with appliances deployed as VPN or access gateways being the primary concern. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2023-10-18 with known ransomware use and a 100% EPSS exploitation probability, although no public proof-of-concept is known at this time. Because tokens stolen from memory can remain valid even after patching, responders must terminate all active and persistent sessions as part of remediation.
Do: Upgrade affected appliances to the patched builds cited in Citrix's advisory, then immediately kill all active and persistent ICA/AAA sessions per the vendor instructions, since patching alone does not invalidate session tokens attackers may have already stolen. If patching is not immediately possible, discontinue use of the affected Gateway/AAA configurations as CISA directs. Given known ransomware abuse, also hunt for signs of exploitation such as logins from unexpected sources, anomalous session reuse, or suspicious mailbox changes, and reset credentials for potentially exposed accounts.
Authenticated Code-Injection RCE in Citrix NetScaler ADC/Gateway
CVE-2023-6548 is a code injection flaw (CWE-94) in the management interface of Citrix NetScaler ADC and NetScaler Gateway that allows remote code execution. It is triggered when an attacker who can reach the appliance's NSIP, CLIP, or a SNIP with management interface access authenticates with valid low-privileged credentials and sends crafted input that the appliance turns into executable code. Successful exploitation yields authenticated remote code execution in the context of the management interface, with high impact on the confidentiality, integrity, and availability of the appliance. Affected organizations are those running Citrix NetScaler ADC or NetScaler Gateway appliances, particularly deployments whose management interfaces are reachable from less-trusted networks or shared with low-privileged users. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-17 and urged immediate action, though no public proof-of-concept code is known and EPSS currently estimates a ~3.2% chance of exploitation within 30 days.
Do: Upgrade affected NetScaler ADC and NetScaler Gateway appliances to the fixed builds in Citrix's security bulletin for CVE-2023-6548 (released alongside the companion CVE-2023-6546 NetScaler privilege-escalation fix), per CISA's KEV directive to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. Reduce exposure by restricting management interface access on the NSIP, CLIP, and SNIPs to trusted admin networks and by removing or constraining low-privileged accounts that do not need management access. Review appliance authentication logs and configurations for unexpected logins or changes, since exploitation requires authenticated access to the management interface.
Out-of-Bounds Read (Memory Overread) in Citrix NetScaler ADC and Gateway
Citrix NetScaler ADC and NetScaler Gateway contain an out-of-bounds read (CWE-125) caused by insufficient input validation, which can cause the appliance to read beyond the intended memory buffer (a memory overread). The flaw is only triggerable when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, so attackers who can reach those services can potentially induce the overread and obtain sensitive memory contents. Such disclosure could aid follow-on compromise, for example by exposing session or authentication data, and CISA notes known ransomware use. Organizations running NetScaler ADC or NetScaler Gateway in the affected Gateway/AAA configurations are exposed. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-10 with known ransomware use and an EPSS of 100% (100th percentile), indicating active exploitation, while no public PoC is known and a CVSS score has not yet been assigned.
Do: Apply the fixed NetScaler ADC/Gateway builds per Citrix's security advisory (exact affected/fixed version ranges are not in the available data, so consult the bulletin); per CISA KEV, apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. Inventory appliances for Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server configurations, since unconfigured/other deployments are not triggerable. After patching, terminate active and idle VPN sessions and hunt for anomalous access, given the known ransomware exploitation and the information-disclosure nature of the flaw.
Memory Buffer Overflow in Citrix NetScaler ADC and Gateway Exploited in the Wild
Citrix NetScaler ADC and NetScaler Gateway appliances contain a memory buffer overflow (CWE-119) that can lead to unintended control flow and denial of service. The flaw is only reachable when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, and it is network-exploitable without authentication or user interaction, though attack complexity is rated high. A successful attacker could achieve unintended control flow — with the CVSS 4.0 vector rating impact high across confidentiality, integrity, and availability — or crash the appliance, disrupting VPN access and application delivery. Any organization running NetScaler ADC or NetScaler Gateway in an affected Gateway/AAA configuration is exposed, a population that public scan data places in the tens of thousands of internet-exposed devices. The vulnerability was added to CISA's KEV catalog on 2025-06-30, confirming exploitation in the wild, with EPSS at 10.1% and no public proof-of-concept known.
Do: Apply the patched NetScaler release specified in Citrix's security bulletin for CVE-2025-6543 immediately, prioritizing appliances in Gateway or AAA configurations, per CISA KEV and BOD 22-01 requirements. Audit which virtual servers (VPN, ICA Proxy, CVPN, RDP Proxy, AAA) are in use and whether they are internet-exposed, and check appliances for signs of compromise before and after upgrading.
Actively Exploited Memory Overflow RCE/DoS in Citrix NetScaler ADC/Gateway
CVE-2025-7775 is a memory overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that can lead to remote code execution and/or denial of service. It is triggered when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or AAA virtual server, or — on 13.1, 14.1, 13.1-FIPS, and NDcPP builds — when load-balancing virtual servers of type HTTP, SSL, or HTTP_QUIC are bound with IPv6 services or servicegroups with IPv6 servers (including DBS IPv6), or a CR virtual server of type HDX is in use. A remote, unauthenticated attacker (CVSS 4.0 network vector with no privileges required) who triggers the memory overflow can execute code with high impact on confidentiality and integrity or crash the device. Organizations running NetScaler in these exposed configurations, notably as remote-access gateways, are affected. Exploitation is confirmed in the wild: Citrix has confirmed active exploitation, the flaw was added to CISA's KEV catalog on 2025-08-26, and EPSS estimates a 19.6% probability of exploitation within 30 days (97th percentile).
Do: Upgrade all NetScaler ADC and Gateway appliances to the patched builds on the 13.1, 14.1, 13.1-FIPS, and NDcPP release trains identified in Citrix's security bulletin, prioritizing internet-facing devices. Audit configurations for Gateway (VPN/ICA Proxy/CVPN/RDP Proxy) or AAA virtual servers, HTTP/SSL/HTTP_QUIC LB virtual servers with IPv6 bindings, and CR virtual servers of type HDX to confirm exposure. The KEV listing makes applying vendor mitigations or the upgrade mandatory for US federal agencies under BOD 22-01.
Unauthenticated Buffer Overflow in Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-19489 is a vulnerability in Citrix NetScaler ADC and NetScaler Gateway classified as a classic buffer overflow (CWE-120), meaning input is copied into a buffer without adequate size checks; it was disclosed by Citrix alongside CVE-2026-19490, the authentication bypass receiving most of the headline attention. Per the CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N), the flaw is reachable over the network by an unauthenticated remote attacker with no user interaction, though detailed trigger conditions are not spelled out in the CVE description. The scoring (VC:L/VI:L/VA:H, base 8.8 High) indicates the primary impact is to availability — likely crashes or denial of service on the appliance — with low confidentiality and integrity impact. All organizations running NetScaler ADC or NetScaler Gateway 14.1 releases through build 73.32, or 13.1 releases through build 63.21, fall within the affected ranges. There is no evidence of exploitation so far: the issue is not in CISA KEV, has no known public proof-of-concept, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days (32nd percentile).
Do: Upgrade affected NetScaler ADC and NetScaler Gateway deployments to the fixed builds identified in Citrix's advisory (see AL26-019 and CISA advisory AV26-833 Update 1); affected ranges are 14.1 through build 73.32 and 13.1 through build 63.21. Until patched, limit internet exposure of appliance interfaces and monitor Citrix channels for signs of exploitation. Also verify whether the same appliances are affected by the related CVE-2026-19490 authentication bypass fixed in the same advisory.
8.8
<1%
Citrix NetScaler ADC (formerly Citrix ADC) 14.1 releases through build 73.32; 13.1 releases through build 63.21
Remote Authentication Bypass in Citrix NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability (CWE-288, 'using an alternate path or channel') that an unauthenticated remote threat actor can exploit. The flaw is triggerable when the appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy deployments, allowing the attacker to bypass authentication without valid credentials. A successful bypass could give an attacker access to VPN-protected or AAA-gated resources as an authenticated user; no CVSS score has been published yet. Organizations running affected NetScaler appliances in these configurations are exposed, and affected version ranges are not specified in the available data, so defenders should consult Citrix advisory AL26-019. The flaw was added to CISA's KEV on 2026-09-09, indicating exploitation in the wild; ransomware use is unknown, no public PoC is known, and EPSS assigns a 3.4% probability of exploitation within 30 days (88th percentile).
Do: Prioritize applying vendor fixes or mitigations per Citrix advisory AL26-019 in line with CISA BOD 26-04, focusing first on internet-facing appliances configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy). Until patched, restrict internet exposure and review VPN/AAA authentication logs for signs of unauthenticated access, following CISA's Forensics Triage Requirements if compromise is suspected.
Out-of-Bounds Read in Citrix NetScaler ADC and Gateway When Used as SAML IDP
CVE-2026-3055 is an out-of-bounds read (CWE-125) in Citrix NetScaler ADC and NetScaler Gateway caused by insufficient input validation when the appliance is configured as a SAML Identity Provider (IDP). An unauthenticated remote attacker can trigger the flaw by sending crafted input to the SAML IDP functionality, causing the appliance to read beyond the bounds of allocated memory and potentially disclose sensitive information from it. The CVSS 4.0 base score of 9.3 (critical) reflects a network-vector flaw requiring no privileges or user interaction. Only organizations running NetScaler ADC or NetScaler Gateway appliances with SAML IDP configured are affected, according to the available data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-30, carries an 87.2% EPSS probability of exploitation within 30 days, has a public proof-of-concept, and headlines indicate active reconnaissance and exploitation against NetScaler deployments, including federal patch directives.
Do: Apply the patched NetScaler ADC and NetScaler Gateway releases from Citrix's advisory as soon as possible, prioritizing internet-facing appliances (exact fixed version numbers are not in this data; check the vendor bulletin). Determine whether SAML IDP is configured on your appliances and, if it is not needed, disable or unbind it as an interim mitigation while reviewing appliance logs for suspicious authentication or reconnaissance traffic. Federal agencies must follow the CISA required action and BOD 22-01 guidance, with CISA directing patching by the stated Thursday deadline.
Memory Buffer Overflow in Citrix NetScaler ADC/Gateway Exploited in the Wild
CVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that applies when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. The flaw is reachable over the network without authentication (CVSS 4.0: AV:N/PR:N), so an unauthenticated attacker can trigger it remotely. Successful exploitation causes unpredictable or erroneous appliance behavior and denial of service, and the high confidentiality score suggests possible disclosure of memory contents; some reporting suggests pre-authentication remote code execution may be possible, though the vendor description emphasizes DoS. Organizations running affected NetScaler appliances in a Gateway or AAA role — a very common configuration for remote access to Citrix virtual apps and desktops — are potentially exposed. The flaw was added to CISA's KEV catalog on 2026-08-26 and is reported as exploited in the wild, with headlines noting the flaw was already patched before exploitation was confirmed.
Do: Upgrade NetScaler ADC and Gateway to the fixed releases identified in Citrix security advisory AV26-645 (Update 3); no fixed version numbers were included in this data, so consult the advisory directly. Prioritize any appliance with an internet-exposed Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, and given the KEV listing and reports of exploitation, perform log and forensics review for signs of prior compromise per CISA's Forensics Triage Requirements — federal agencies must comply with BOD 26-04 timelines. Where patching cannot happen immediately, restrict or disable exposed Gateway/AAA configurations as an interim mitigation.
Citrix ADC (NetScaler ADC) firmware All builds before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18
Citrix Gateway / NetScaler Gateway firmware All builds before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14, and 10.5-70.18
Citrix SD-WAN WAN-OP (WANOP appliance) firmware All builds before 11.1.1a, 11.0.3d, and 10.2.7
mass≈100,000+ internet-exposed Citrix ADC/Gateway appliances per public internet scans, with a substantially larger total installed base including internal…
KEV
PoC
Citrix NetScaler ADC Supported releases before the July 2023 fixes, per Citrix advisory: 14.1 before 14.1-8.50; 13.1 before 13.1-49.13; 13.0 before 13.0-82.45; 12.1 before 12.1-55.3
Citrix NetScaler Gateway Same affected builds as NetScaler ADC (before 14.1-8.50, 13.1-49.13, 13.0-82.45, 12.1-55.300, and FIPS/NDcPP equivalents); affected when the appliance serves as
largetens of thousands of internet-exposed NetScaler Gateway/ADC appliances (order 10k-100k at disclosure), serving hundreds of thousands to millions of downstream…
KEV
Citrix NetScaler ADC and NetScaler Gateway
masshundreds of thousands of internet-exposed NetScaler ADC/Gateway appliances (public internet scan counts), plus an unknown number of VPN-only or internal…
large~tens of thousands of NetScaler appliances with reachable management interfaces (out of a very large global installed base)
KEV
Citrix NetScaler ADC
Citrix NetScaler Gateway
massplausibly hundreds of thousands of installed/internet-exposed NetScaler ADC and Gateway appliances (public scans have historically shown on the order of…
Citrix NetScaler ADC 13.1, 14.1, 13.1-FIPS, and NDcPP branches; vulnerable when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server; or with
Citrix NetScaler Gateway 13.1, 14.1, 13.1-FIPS, and NDcPP branches; vulnerable when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
large≈28,000+ internet-exposed NetScaler instances per public scans; total vulnerable deployments likely higher
14.1 releases through build 73.32; 13.1 releases through build 63.21
mass≈100,000+ internet-exposed NetScaler ADC/Gateway appliances (order-of-magnitude estimate; not all run affected builds)
Citrix NetScaler ADC and NetScaler Gateway
largeon the order of 10,000-100,000 internet-exposed NetScaler ADC/Gateway appliances
KEV
Citrix NetScaler ADC
Citrix NetScaler Gateway
largetens of thousands of internet-exposed NetScaler ADC/Gateway appliances, with the directly exposed subset limited to those configured as SAML IDPs
KEV
Citrix NetScaler ADC
Citrix NetScaler Gateway
largeTens of thousands of internet-exposed appliances (a Gateway/AAA-configured subset of the roughly 100k+ NetScaler devices visible in public internet scans) —…