Security researchers warned on September 26 that two unpatched Citrix NetScaler ADC and Gateway vulnerabilities allowing remote code execution were being exploited in the wild. Organizations using the affected appliances should treat the alert as an incident-response priority: identify exposed instances, apply vendor guidance as soon as it is available, and review authentication, administrative, and appliance logs for suspicious activity.
Because the reported issue affects edge infrastructure, defenders should also validate segmentation and rotate credentials or tokens that may have been accessible from the appliance. This report describes active exploitation; it does not establish that every exposed deployment has been compromised.
Source: The Hacker News
