watchTowr says two unpatched NetScaler RCE flaws are being exploited and Citrix has published no fix.
Citrix fixed a CVSS 9.3 authentication bypass in NetScaler ADC and Gateway that attackers are expected to exploit quickly.
Attackers are exploiting a Citrix NetScaler memory disclosure flaw to steal active session tokens and deploy ransomware in under an…