A serious situation is developing around Citrix NetScaler ADC and Gateway. Managed service providers, MDR teams, and security organizations are reportedly advising customers to take internet-facing NetScaler appliances offline following warnings about two previously undisclosed vulnerabilities reportedly enabling unauthenticated remote code execution. What makes this particularly concerning is the timing. There are reportedly no public CVEs, no public patch, and limited technical details available so far. Organizations are reportedly being advised to shut down affected appliances rather than simply wait for a patch, with Citrix expected to release fixes early next week.



At my company, we moved out of it to haproxy and nginx