Citrix patches NetScaler flaw enabling remote code execution
Citrix has released security updates to fix a critical vulnerability in NetScaler ADC and NetScaler Gateway that could allow remote code execution or denial of service, particularly when configured as a SAML identity or service provider. The flaw, classified as a memory overflow issue and rated 9.5 on the CVSS scale, has not yet been exploited. Citrix recommends customers upgrade affected systems to the latest versions to mitigate risk.
- Memory overflow flaw in NetScaler rated CVSS 9.5
- Affects SAML IdP or SP configurations
- No exploitation observed so far
- Patches available for multiple NetScaler versions
- Discovered by JPMorgan Chase XOR Team and Maxim Suhanov
Sources covering this
How it unfolded
- SecurityWeek Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
- The Hacker News Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
- BleepingComputer Citrix warns admins to patch new NetScaler RCE flaw immediately
- The Register Citrix gives NetScaler admins another critical reason to patch
More in Cybersecurity
Hackers hijack ccTLDs to forge Google certificates
Attackers gained control of the main domain registries for Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as), allowing them to…
US and allies disrupt Chinese hacking tools targeting infrastructure
US authorities and international partners have seized domains and tools used by China's Integrity Technology Group to support…
AI-powered attacks target South Korean banks
A cyberattack campaign targeting South Korean financial institutions used AI-based tools to steal personal data, CrowdStrike reported.
Metasploit adds modules for recent and legacy vulnerabilities
The latest Metasploit update includes 12 new modules targeting a range of vulnerabilities, from newly identified flaws in AI and server…