A serious situation is developing around Citrix NetScaler ADC and Gateway. Managed service providers, MDR teams, and security organizations are reportedly advising customers to take internet-facing NetScaler appliances offline following warnings about two previously undisclosed vulnerabilities reportedly enabling unauthenticated remote code execution. What makes this particularly concerning is the timing. There are reportedly no public CVEs, no public patch, and limited technical details available so far. Organizations are reportedly being advised to shut down affected appliances rather than simply wait for a patch, with Citrix expected to release fixes early next week.
When my old job still used Citrix for customers, 90% of our support calls would be about that. We spent, if that, 10% of the time actually troubleshooting our own software. Most of it was certificates included with Receiver not being fully validated or even being fucking revoked. Fun times.
At my company, we moved out of it to haproxy and nginx
Netscalers have always been Swiss cheese. No idea why they are or why they weren’t rebuilt from the ground up.



