Citrix NetScaler - 2 ongepatchte RCE-zero-days

Pagina: 1
Acties:

  • crunchytail
  • Registratie: Oktober 2013
  • Laatst online: 22:55
Heads-up voor de beheerders van Citrix NetScaler omgevingen:

The Hacker News - Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.

Citrix has not confirmed the flaws or published a fix. Some administrators say they have taken appliances offline rather than wait for one to be available.

NetScaler ADC and NetScaler Gateway sit at the edge of enterprise networks, where they handle VPN and remote access, load balancing, and user authentication.

The new flaws are not the authentication bypass, CVE-2026-19490, that Citrix fixed on August 19 and that CISA added to its Known Exploited Vulnerabilities catalog on September 9.

watchTowr described the new flaws as unpatched, and a fix for the bypass has existed since August 19. Citrix has not said whether appliances on the August builds, 14.1-73.32 and 13.1-63.21, or any newer builds, are affected by the new flaws.

watchTowr's first post on X on September 26 said it was reacting to rumors of several unpatched NetScaler RCE vulnerabilities in the wild. "While details are scarce, the information is credible," it wrote.

A follow-up post at 22:19 UTC gave the fuller account: two vulnerabilities, both remote code execution, both unpatched, exploited before any fix existed, discovered during forensic investigations, and Citrix communications and patches expected early in the week of September 28. It directed further questions to Citrix.

The firm has published no evidence, named no victim, and has not said whose forensic investigations found the exploitation. In August it showed that a NetScaler heap overflow Citrix had patched in June could be used for remote code execution.

Reports of shutdown advice appeared on Reddit the same day. An administrator posting on r/Citrix wrote that their IT supplier's security team had phoned to advise shutting their NetScalers down immediately, without giving details. Others in the thread said their organizations had done the same.

The source of the suppliers' warning is not established. With no bulletin, there is no vendor workaround, and no indicators of compromise for the new flaws have been published. Until a fix ships, the decision for anyone running a NetScaler is whether to keep it online, isolate it, or power it off, and whether to treat it as already compromised.

Because the exploitation, as watchTowr describes it, happened before any fix existed, installing the fix will not tell an operator whether an attacker got in first.

  • crunchytail
  • Registratie: Oktober 2013
  • Laatst online: 22:55
Er is een update beschikbaar. Nu ook een waarschuwing vanuit NCSC:

Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu

https://www.ncsc.nl/alert...tscaler-gateway-update-nu

Er is een aantal kwetsbaarheden gevonden in Citrix NetScaler ADC en NetScaler Gateway. De ernst van deze kwetsbaarheden varieert, met CVSS-scores tot 9,5. De kwetsbaarheden betreffen verschillende beveiligingsproblemen die onder meer kunnen leiden tot het omzeilen van beveiligingsmaatregelen, het onbruikbaar maken van de NetScaler en het uitvoeren van malafide code op het systeem. Twee van deze kwetsbaarheden worden al misbruikt. Citrix heeft updates uitgebracht. Het NCSC adviseert om deze zo snel mogelijk te installeren.

  • F_J_K
  • Registratie: Juni 2001
  • Niet online

F_J_K

Moderator CSA/PB/AI

Front verplichte underscores

'Multiple exclamation marks,' he went on, shaking his head, 'are a sure sign of a diseased mind' (Terry Pratchett, Eric)