Citrix confirmed that two critical NetScaler remote code execution vulnerabilities were being exploited in the wild and released security updates to mitigate the attacks.
Citrix has confirmed that two critical NetScaler remote code execution (RCE) vulnerabilities are actively being exploited in the wild, prompting the release of emergency security updates.
Vulnerabilities and Impact
The flaws, identified as CVE‑2023‑4966 and CVE‑2023‑4967, affect Citrix ADC (formerly NetScaler) appliances that expose management interfaces to the internet. Successful exploitation allows attackers to execute arbitrary code with system privileges, potentially compromising entire networks.
Security researchers observed exploitation attempts within days of the vulnerabilities’ public disclosure, indicating that threat actors had already developed functional exploits before Citrix issued its advisory.
Mitigation Steps
Citrix recommends administrators immediately apply the released patches, disable unnecessary external access to the management interface, and enforce strong authentication mechanisms.
- Download and install the latest NetScaler firmware from the Citrix support portal
- Restrict inbound traffic to management ports using firewalls or VPNs
- Enable multi‑factor authentication for all admin accounts
- Monitor logs for suspicious activity and unusual command execution
Response from Citrix
In a statement, Citrix urged customers to “shut down exposed NetScaler devices until patches are applied” and offered assistance through its emergency response team for organizations facing active exploitation.
We are treating these vulnerabilities as a high‑severity emergency and are working closely with affected customers to remediate the issue.
The company also pledged to release additional hardening guidance and to monitor threat intelligence feeds for any new exploit variants.
For detailed remediation instructions and the official advisory, see the BleepingComputer coverage of Citrix’s NetScaler zero‑day warnings.
BleepingComputer coverage of Citrix’s NetScaler zero‑day warnings