Citrix fixes eight NetScaler flaws as attackers exploit two critical bugs

← Back to the feed

Citrix fixes eight NetScaler flaws as attackers exploit two critical bugs

The Register · 2 hours ago

Citrix has disclosed eight vulnerabilities in its NetScaler application delivery controller and gateway products, including two critical flaws that allow remote code execution and are already being exploited. The US Cybersecurity and Infrastructure Security Agency says it has reports of attackers exploiting the vulnerabilities globally, and has urged organisations to assess their exposure and prioritise mitigation.

A third critical flaw could enable HTTP request smuggling, while five other bugs include memory overflows, a TCP sequence-number prediction issue and a feature-policy bypass. Citrix has released operating system updates containing fixes and guidance on checking affected appliances. The article notes that NetScaler flaws have repeatedly been exploited in recent years, although patching can be difficult because updates may require downtime.

  • Attackers are exploiting critical NetScaler vulnerabilities worldwide.
  • Citrix has released fixes and guidance for affected appliances.
  • NetScaler has a recurring history of serious, exploited flaws.

Americas World

Read the full article at the source →

Originally published by The Register as “Certainties in life: Death, taxes, and critical Citrix vulns under attack”.