Citrix NetScaler Zero-Day Flaws Exploited in the Wild

Citrix Confirms Active Zero-Day Exploitation of Two Critical NetScaler Flaws

Citrix has disclosed two critical vulnerabilities in NetScaler ADC and NetScaler Gateway that were exploited as zero-days before patches were released. The flaws—CVE-2025-24046 and CVE-2025-24047—allow unauthenticated remote code execution on vulnerable appliances. Organizations using NetScaler products face immediate risk and must apply emergency patches while investigating potential compromise of their application delivery infrastructure.

Introduction

Zero-day vulnerabilities in enterprise infrastructure represent one of the most severe security scenarios organizations face. When attackers discover and exploit flaws before vendors can issue patches, the window of exposure leaves critical systems completely defenseless. Citrix has now confirmed that two newly disclosed NetScaler vulnerabilities fall into this dangerous category—both were actively exploited in the wild before mitigation measures became available.

NetScaler ADC (formerly NetScaler) and NetScaler Gateway serve as critical components in enterprise application delivery and remote access infrastructure. These appliances sit at network perimeters, handling authentication, load balancing, and secure access to corporate resources. Their privileged position makes them high-value targets for sophisticated threat actors seeking initial access to enterprise environments.

The confirmation of active exploitation elevates these vulnerabilities from theoretical risks to confirmed threats with demonstrated attacker capability and intent.

Background & Context

NetScaler products from Citrix power application delivery for thousands of organizations worldwide, including Fortune 500 companies, healthcare providers, financial institutions, and government agencies. These appliances process authentication credentials, decrypt SSL/TLS traffic, and maintain persistent access to internal networks—making them attractive targets for both cybercriminals and nation-state actors.

This isn’t the first time NetScaler products have faced zero-day exploitation. In 2023, CVE-2023-3519 (Citrix Bleed) was weaponized by multiple threat groups, leading to widespread compromise of enterprise networks. That incident demonstrated the real-world consequences of NetScaler vulnerabilities and established these products as confirmed targets for advanced persistent threats.

The current vulnerabilities, CVE-2025-24046 and CVE-2025-24047, continue this troubling pattern. Both flaws exist in NetScaler ADC and NetScaler Gateway, affecting multiple product versions deployed across enterprise environments.

Technical Breakdown

CVE-2025-24046 is a buffer overflow vulnerability that allows remote unauthenticated attackers to execute arbitrary code on vulnerable NetScaler appliances. The flaw exists in the processing of specially crafted network packets, where insufficient bounds checking enables attackers to overwrite memory and gain control of execution flow.

CVE-2025-24047 represents a related but distinct remote code execution vulnerability, also exploitable without authentication. While Citrix has not disclosed complete technical details—likely to prevent widespread exploitation—the vulnerability appears to involve improper input validation in network-facing services.

Both vulnerabilities carry CVSS scores in the critical range, reflecting their remote exploitability, lack of authentication requirements, and potential for complete system compromise.

The attack chain for these vulnerabilities follows a predictable pattern:

  • Attackers identify exposed NetScaler appliances through internet scanning
  • Specially crafted requests exploit the vulnerabilities to achieve code execution
  • Attackers establish persistence and deploy additional tools
  • Lateral movement begins from the compromised appliance into the internal network

Evidence suggests threat actors exploited these flaws before public disclosure, meaning some organizations may already be compromised without knowledge of the initial access vector.

Impact & Risk Assessment

The impact of these vulnerabilities extends far beyond the NetScaler appliances themselves. Successful exploitation grants attackers a foothold in the most sensitive part of enterprise infrastructure—the security perimeter.

Immediate risks include:

  • Complete appliance compromise: Attackers gain root-level access to NetScaler systems
  • Credential theft: All authentication traffic passing through compromised appliances is accessible
  • SSL/TLS decryption: Encrypted traffic is visible in cleartext to attackers controlling the appliance
  • Lateral movement: Compromised perimeter devices provide ideal launching points for internal network attacks
  • Persistence: Attackers can maintain long-term access even after other security improvements

Organizations in specific sectors face elevated risk:

  • Healthcare providers using NetScaler for HIPAA-compliant remote access
  • Financial institutions relying on NetScaler for secure transaction processing
  • Government agencies with classified or sensitive data accessible through affected gateways
  • Critical infrastructure operators where NetScaler controls access to operational technology

The confirmed zero-day exploitation means some organizations were compromised before patches existed. These victims face the challenging task of identifying historical compromise through forensic analysis of systems that may have been deliberately manipulated by sophisticated attackers.

Vendor Response

Citrix released security bulletin CTX677410 addressing both vulnerabilities with emergency patches across affected product lines. The company confirmed active exploitation in their advisory, an unusual disclosure that underscores the severity and immediacy of the threat.

Patched versions include:

  • NetScaler ADC and Gateway 14.1-25.100 and later
  • NetScaler ADC and Gateway 13.1-55.100 and later
  • NetScaler ADC and Gateway 13.0-94.100 and later
  • NetScaler ADC 13.1-FIPS 13.1-37.201 and later
  • NetScaler ADC 12.1-FIPS 12.1-55.329 and later
  • NetScaler ADC 12.1-NDcPP 12.1-55.329 and later

Citrix has urged customers to apply patches immediately and investigate potential compromise. The company worked with security researchers and incident responders who identified the zero-day exploitation in customer environments.

Unlike some vendors who delay disclosure while tracking threat actor activity, Citrix opted for immediate public notification—prioritizing customer security over intelligence gathering.

Mitigations & Workarounds

Organizations unable to immediately patch should implement the following mitigations:

Network-level controls:

  • Restrict NetScaler management interface access to trusted IP addresses only
  • Implement additional authentication layers for administrative access
  • Deploy web application firewalls in front of NetScaler appliances where architecturally feasible

Monitoring enhancements:

  • Enable comprehensive logging for all NetScaler authentication events
  • Export logs to external SIEM platforms to prevent attacker log manipulation
  • Establish baseline behavior patterns for anomaly detection

Emergency response measures:

show ns runningConfig | grep "add system user"
show ns runningConfig | grep "add lb vserver"

# Check for unauthorized SSL certificates
show ssl certKey

# Examine recent login events
cat /var/log/ns.log | grep -i "login"

Temporary risk reduction:

  • Consider temporarily disabling external access to non-critical applications
  • Implement temporary VPN alternatives for remote access if NetScaler Gateway must be taken offline
  • Increase authentication requirements for accessing resources through NetScaler

These workarounds provide partial risk reduction but cannot fully eliminate exposure. Patching remains the only complete mitigation.

Detection & Monitoring

Organizations should search for indicators of historical and ongoing compromise:

File system artifacts:

# Check for suspicious processes
ps aux | grep -v "^\[" | grep -v "grep"

# Examine recently modified system files
find /netscaler -type f -mtime -30 -ls
find /var -type f -mtime -30 -ls

# Review cron jobs and scheduled tasks
cat /etc/crontab
ls -la /var/spool/cron/crontabs/

Network indicators:

  • Unusual outbound connections from NetScaler appliances
  • Authentication attempts from unexpected geographic locations
  • Successful logins followed by immediate configuration changes
  • SSL certificate additions without corresponding change tickets

Configuration anomalies:

  • Unauthorized user accounts, especially with administrative privileges
  • New load balancing rules directing traffic to suspicious destinations
  • Modified authentication policies weakening security controls
  • Unexpected SSL certificate installations

Behavioral indicators:

  • Spike in failed authentication attempts preceding successful compromise
  • Configuration exports or backups initiated outside maintenance windows
  • Administrative actions during unusual hours
  • Rapid succession of privilege escalation activities

Organizations should assume compromise if NetScaler appliances were internet-accessible during the zero-day window and conduct thorough forensic examinations.

Best Practices

Beyond immediate patching, organizations should implement long-term security improvements for application delivery infrastructure:

Architecture improvements:

  • Deploy NetScaler appliances behind additional security layers where possible
  • Segment management interfaces from production traffic flows
  • Implement network access controls preventing lateral movement from compromised appliances

Operational security:

  • Establish dedicated monitoring for all perimeter security devices
  • Maintain offline configuration backups for rapid clean recovery
  • Implement privileged access management for administrative functions
  • Conduct regular security assessments of NetScaler configurations

Incident preparedness:

  • Develop and test incident response playbooks specific to NetScaler compromise
  • Establish procedures for rapid appliance replacement or rebuild
  • Maintain alternative remote access methods for scenarios requiring NetScaler shutdown
  • Create communication plans for notifying users of authentication system compromise

Vulnerability management:

  • Subscribe to Citrix security bulletins for immediate notification
  • Prioritize NetScaler patching above general infrastructure updates
  • Test patches in staging environments while maintaining aggressive deployment timelines
  • Conduct post-patch validation to confirm successful remediation

Key Takeaways

  • Two critical NetScaler vulnerabilities were exploited as zero-days before patches became available
  • Both CVE-2025-24046 and CVE-2025-24047 enable remote code execution without authentication
  • NetScaler’s position at network perimeters makes these vulnerabilities particularly dangerous
  • Organizations must immediately patch affected systems and investigate potential historical compromise
  • The confirmed exploitation demonstrates active targeting of NetScaler infrastructure by sophisticated threat actors
  • Perimeter security devices require enhanced monitoring and rapid patch deployment processes
  • Assumed breach scenarios should guide investigation efforts for internet-exposed NetScaler appliances

References

  • Citrix Security Bulletin CTX677410
  • Citrix NetScaler Product Documentation
  • CVSS v3.1 Vulnerability Scoring Guide
  • CISA Known Exploited Vulnerabilities Catalog

Stay updated at https://cydhaal.com — Your Daily Dose of Cyber Intelligence.
📧 Subscribe to our newsletter at https://cydhaal.com/newsletter/


Leave a Reply

Your email address will not be published. Required fields are marked *

💬 Join WhatsApp Channel 📲 Cydhaal App