Citrix has issued an urgent warning to administrators regarding two zero-day vulnerabilities in NetScaler ADC and Gateway, identified as CVE-2023-6548 and CVE-2023-6549. These flaws are being actively exploited in the wild, with one allowing for remote code execution (RCE) on the management interface and the other facilitating denial-of-service (DoS) attacks.
Citrix recommends immediate patching to the latest firmware versions. If patching is not immediately feasible, administrators are advised to restrict access to the management console to internal networks or trusted IPs to mitigate the risk of exploitation on the RCE vulnerability.
Top comments (0)