ZeroFox Intelligence Flash Report - Citrix Vulnerabilities Continue to Be Exploited
|by Alpha Team

ZeroFox Intelligence Flash Report - Citrix Vulnerabilities Continue to Be Exploited
Product Serial: F-2024-01-17c
TLP:CLEAR
In this flash report, ZeroFox researchers report on the ongoing exploitation of three separate Citrix vulnerabilities relating to Netscaler Application Delivery Controller (ADC) and Gateway appliances.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- Threat actors continue to exploit three separate Citrix vulnerabilities relating to Netscaler Application Delivery Controller (ADC) and Gateway appliances, which is likely indicative of a significant number of networks comprising this equipment remaining unpatched.
- On January 16, 2024, Citrix urged consumers to update software relating to actively-exploited zero-day vulnerabilities CVE-2023-6548 and CVE-2023-6549.
- An article published on January 14, 2024, in dark web forum xss. provides instructions on how CVE-2023-4966 can be exploited, with its reception being indicative of a continued interest amongst threat actors.
Tags: tlp:clear, dark web, vulnerability/exploit, threat actor