Citrix has released an urgent security update to patch a critical remote code execution (RCE) vulnerability in its NetScaler ADC and NetScaler Gateway products. This flaw, actively exploited in the wild, allows attackers to execute arbitrary code on vulnerable systems, posing a significant risk to enterprise networks. The vulnerability, tracked as CVE-2024-28497, affects multiple versions of NetScaler ADC and Gateway, widely used for application delivery and secure remote access. Exploitation of this zero-day vulnerability has been observed in targeted attacks, emphasizing the need for immediate patching to prevent potential breaches. Citrix has urged all customers to apply the security update without delay to mitigate the risk of exploitation. The incident highlights the ongoing threat landscape where critical infrastructure components are prime targets for sophisticated attackers. Organizations using NetScaler products should also review their security monitoring and incident response plans to detect any signs of compromise related to this vulnerability. This update is part of Citrix's commitment to maintaining secure products and protecting customers from emerging cyber threats. Staying informed and proactive in applying patches is essential for cybersecurity resilience in today's environment.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Tue, 26 Aug 2025 21:40:19 +0000