CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

Citrix NetScaler Flaws Wreak Havoc on Global Networks as CISA Issues Urgent Warning

The US Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm, warning that attackers are actively exploiting two critical vulnerabilities in Citrix’s NetScaler product. The flaws, which have been identified as CVE-2023-0664 and CVE-2023-0671, allow hackers to gain unauthorized access to sensitive systems and data. As a result, organizations worldwide are urged to take immediate action to mitigate the risks.

Citrix NetScaler is a popular application delivery controller (ADC) used by many companies to manage traffic flow between their internal networks and external clients. The ADC acts as an intermediary, optimizing performance and securing communications. However, in this case, the security of these systems has been compromised due to the presence of two severe vulnerabilities. Attackers can exploit these flaws to gain admin-level access, allowing them to create backdoors, steal sensitive information, or even take control of entire networks.

The attack vector is particularly concerning because it involves a technique called cross-domain privilege escalation (CDPE). This allows hackers to bypass security measures and move laterally within a network, essentially creating an “attack path” from one system to another. By exploiting these vulnerabilities, attackers can effectively create a “bypass” around traditional security controls, making it easier for them to breach sensitive areas of the network.

The CISA warning is clear: this is not just a theoretical threat, but a real-world issue that requires immediate attention. Citrix has issued patches and guidance to help affected organizations protect themselves, but the window for action is rapidly closing. The longer it takes for administrators to apply these fixes, the greater the risk of successful exploitation by attackers.

The global impact of this vulnerability cannot be overstated. Organizations relying on Citrix NetScaler must take swift action to prevent potential breaches. This may involve patching systems, conducting thorough security audits, and reconfiguring network architectures to minimize exposure. In short, organizations cannot afford to wait – the stakes are too high.

In light of this urgent warning, we urge all readers to prioritize their NetScaler deployments and ensure that they are up-to-date with the latest patches and configuration best practices. Remember: preventing these types of attacks often comes down to having a solid security posture in place. This includes staying informed about emerging threats, maintaining vigilant monitoring, and engaging in proactive maintenance routines to stay one step ahead of potential attackers.


Source: The Hacker News — 2026-09-28