Our takeCCCS updated its Citrix advisory (AV26-833) on flaws in NetScaler ADC and Gateway before 14.1-73.32 and 13.1-63.21. Update if you run them.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — Security leader:Update NetScaler ADC, Gateway, FIPS, and NDcPP builds to 14.1-73.32+, 13.1-63.22+, or the listed FIPS/NDcPP minimums. Check for internet exposure and apply mitigations if patching cannot be done immediately.
What this means for you — Lean IT orgs:If you run a NetScaler ADC or Gateway, update it to version 14.1-73.32 or 13.1-63.22 (or newer) as soon as you can. If you are not sure whether you have one, ask your IT provider to check.
What this means for you — MSP:Audit all managed NetScaler ADC and Gateway instances (including FIPS and NDcPP builds) and upgrade them to 14.1-73.32+, 13.1-63.22+, or the listed minimums. Confirm none are unnecessarily internet-facing.
What this means for you — Researcher:Review the updated Citrix/NetScaler builds and associated advisories for the fixes in this round.