Security researchers at watchTowr disclosed on September 26 that two previously unknown vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are being actively exploited in the wild. Both flaws allow remote code execution, according to the firm, but Citrix has not yet confirmed the issues or released a patch.

NetScaler ADC and NetScaler Gateway are widely deployed application delivery controllers and remote access gateways used by enterprises to manage traffic and provide secure VPN-style access to internal networks. Because these appliances typically sit at the network edge and handle authentication, vulnerabilities of this class have historically been high-value targets for both opportunistic and targeted attackers.

No Patch, No Confirmation Yet

As of the disclosure, Citrix has not issued a security bulletin, assigned tracking identifiers, or confirmed the technical details of either vulnerability. That leaves administrators without official guidance on affected versions or a timeline for a fix.

In the absence of a patch, some organizations have reportedly chosen to take affected NetScaler appliances offline entirely rather than leave them exposed to active exploitation. This is a drastic but not unprecedented response for edge devices that have repeatedly been targeted in prior Citrix vulnerability episodes.

What Defenders Should Do Now

Security teams running NetScaler ADC or NetScaler Gateway should treat this as an active incident rather than a routine advisory:

  • Monitor Citrix’s official security bulletin page closely for updates and patch availability
  • Review NetScaler logs and network traffic for signs of anomalous activity or unauthorized access
  • Consider restricting external access to management interfaces where feasible
  • Evaluate whether temporarily taking exposed appliances offline is warranted given exploitation activity
  • Prepare to apply an emergency patch as soon as Citrix publishes one

Given NetScaler’s role as a perimeter device handling authentication and remote access, unpatched remote code execution flaws under active exploitation represent a significant risk. Organizations should treat this situation with urgency until Citrix provides official confirmation and remediation guidance.