Two remote-code-execution zero-days in Citrix NetScaler ADC and NetScaler Gateway appliances are being actively exploited right now, with no CVE number, no vendor advisory, and no patch available as of this week. Security firm watchTowr said it found the attacks while investigating already-compromised customer environments — meaning the flaws surfaced because criminals were already using them, not because a researcher caught them in a lab first. The Dutch national cyber security centre (NCSC-NL) had quietly pre-warned organisations days earlier. Citrix has acknowledged it is working on a fix, expected early in the week of 28 September, but has not yet said which appliance versions are vulnerable.
NetScaler ADC and Gateway sit at the edge of a network, handling VPN logins, load balancing, and remote access — exactly the kind of internet-facing box that attackers target first and defenders notice last. Adding to the risk: the NetScaler 13.1 branch reached end-of-maintenance on 15 September, so any business still running it has no vendor fix coming at all once one ships for supported versions. Because exploitation began before any fix existed, simply installing next week's patch will not by itself tell you whether an attacker already got in.
What this means for your business
If your business runs a Citrix NetScaler ADC or Gateway appliance — often set up by an IT provider for VPN or remote-office access — ask directly, today, whether it is reachable from the internet. If it is, either take it offline or lock its management interface down to a short list of trusted IP addresses until Citrix ships a fix, and apply that patch immediately once it lands. Because the attacks predate any fix, also treat the appliance as possibly already compromised in the meantime: have whoever manages it check recent access logs for unfamiliar logins and rotate any passwords or certificates tied to the device. If you are not sure whether your business even has a NetScaler appliance — many are installed once and forgotten — this is the week to find out.