Critical NetScaler zero-days demand immediate patch
🔒 Citrix has confirmed two critical unauthenticated remote code execution zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway that are under active exploitation and must be patched immediately. Citrix released fixes in versions 14.1-73.37 and later and 13.1-64.23 and later, and urged customers to install updates as soon as possible. The US CISA added both to its KEV catalog while Citrix published additional mitigations, IOCs and fixes for six other related vulnerabilities.
