DEV Community

Cover image for Citrix NetScaler Appliance Users Get Shutdown Orders Over Unpatched Zero-Day Exploits
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Citrix NetScaler Appliance Users Get Shutdown Orders Over Unpatched Zero-Day Exploits

Summary

Citrix NetScaler ADC and Gateway appliances are facing active exploitation of two unpatched remote code execution vulnerabilities. The Dutch NCSC and security firm watchTowr advised organizations to take systems offline until Citrix releases patches next week.

Take Action:

If you run Citrix NetScaler ADC or Gateway, this is urgent. The devices are actively attacked and there is no patch for the exploited flaws. Either shut the devices immeidately, or if the devices must stay online block all internet access to their management ports and allow access to the devices only from a short list of trusted IP addresses. Watch for new files in the crash dumps folder as a sign of compromise, and install Citrix's official patches as soon as they come out.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)