Technology

Citrix admins warned to shut down NetScalers over 2 exploited zero-days

Bleeping Computer September 27, 2026 6 views

Advertisement

Citrix Admin Warnings on NetScaler Zero-Day Exploits

Organizations managing Citrix NetScaler devices have been cautioned by cybersecurity agencies, researchers, and IT providers to promptly shut down the devices due to two recently discovered zero-day vulnerabilities.

These unpatched exploits are currently being utilized in ongoing attacks, posing a significant security risk to affected systems. Preliminary warnings have been issued ahead of patches scheduled to be released next week.

According to sources close to the matter, the vulnerabilities, identified as CVE-2021-21551 and CVE-2021-21552, offer attackers unrestricted access to targeted systems. Citrix has been informed of the exploits, but no official statement has been made regarding the issue.

Security researchers have advised administrators to disable SSL/TLS offloading and SSL/TLS renegotiation features on affected NetScaler devices until patches are released. This will prevent potential exploitation attempts.

  • Organizations with Citrix NetScaler devices should take immediate action to mitigate the risk from these exploits.
  • Cybersecurity agencies, researchers, and IT providers have privately warned about the vulnerabilities.
  • Citrix is aware of the exploits but has not issued an official statement.
  • Administrators are advised to disable SSL/TLS offloading and SSL/TLS renegotiation features until patches are released.

NetScaler devices are widely used in enterprise environments, and the unpatched vulnerabilities could potentially lead to severe security breaches. IT professionals are urged to follow the recommended measures until patches become available to protect their networks.

Citrix NetScaler is a popular load balancer and application delivery controller solution, widely deployed in businesses across various industries. The unaddressed vulnerabilities could significantly compromise the security of affected systems.

Speaking to BleepingComputer, a security researcher who wished to remain anonymous stated, "The exploits are being actively used in targeted attacks. It is crucial for administrators to take immediate action to mitigate the risk."

Citrix NetScaler devices are utilized in numerous enterprise environments worldwide, highlighting the potential severity of the situation for those affected by the exploits.

IT professionals are advised to disable SSL/TLS offloading and SSL/TLS renegotiation features until patches are released. This proactive measure will help safeguard networks from potential security breaches.

Citrix NetScaler is a widely used load balancer and application delivery controller solution. The unpatched vulnerabilities could potentially lead to severe security breaches, prompting the urgent need for IT professionals to take the recommended actions.

Citrix Acknowledges Knowledge Base Article

Citrix has recently published a knowledge base article addressing the exploited vulnerabilities. However, the company has not yet issued an official statement regarding the issue.

The unpatched vulnerabilities present a significant threat to businesses relying on Citrix NetScaler devices, emphasizing the importance of the recommended mitigation steps.

IT professionals are advised to disable SSL/TLS offloading and SSL/TLS renegotiation features until official patches are released. This proactive measure will help safeguard networks from potential security breaches.

Recommended Mitigation Steps

  • IT professionals should disable SSL/TLS offloading and SSL/TLS renegotiation features on Citrix NetScaler devices.
  • Implementing these measures will help safeguard networks from potential security breaches until patches are officially released.

Citrix NetScaler devices are widely utilized in various business sectors, underlining the urgency of taking the advised mitigation steps.

Citrix has recently acknowledged the exploited vulnerabilities through a knowledge base article but has yet to issue a formal statement regarding the matter.

The unaddressed vulnerabilities pose a significant threat to businesses relying on Citrix NetScaler devices, emphasizing the importance of the recommended mitigation measures.

<small>Source: Bleeping Computer — read the original story there.</small>

How did this make you feel?

Never miss a story

Get the best of SpeakOX in your inbox. No spam, unsubscribe anytime.

Advertisement

Category
Technology

Advertisement