Our takeCCCS updated its Citrix advisory (AV26-645) on critical flaws in NetScaler ADC and Gateway before 14.1-72.61 and 13.1-63.18. Update if you run them.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — Security leader:Citrix advisory AV26-645 confirms active exploitation of critical flaws in NetScaler ADC and Gateway (pre-14.1-72.61 and pre-13.1-63.18). Patch to the fixed builds immediately and review internet-exposed instances.
What this means for you — Lean IT orgs:If you run a Citrix NetScaler ADC or Gateway, update it to version 14.1-72.61 or 13.1-63.18 right away. Attackers are already exploiting these flaws.
What this means for you — MSP:Audit all client NetScaler ADC and Gateway deployments for versions before 14.1-72.61 or 13.1-63.18 and push the Citrix patches; active exploitation is confirmed.
What this means for you — Researcher:Citrix AV26-645 (updated Aug 17) lists critical vulnerabilities in NetScaler ADC/Gateway with confirmed active exploitation. Fixed in 14.1-72.61, 13.1-63.18 and corresponding FIPS build.