zerofox logo
Advisories

ZeroFox Intelligence Flash Report - Citrix Vulnerabilities Continue to Be Exploited

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - Citrix Vulnerabilities Continue to Be Exploited

Product Serial: F-2024-01-17c

TLP:CLEAR

In this flash report, ZeroFox researchers report on the ongoing exploitation of three separate Citrix vulnerabilities relating to Netscaler Application Delivery Controller (ADC) and Gateway appliances.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • Threat actors continue to exploit three separate Citrix vulnerabilities relating to Netscaler Application Delivery Controller (ADC) and Gateway appliances, which is likely indicative of a significant number of networks comprising this equipment remaining unpatched.
  • On January 16, 2024, Citrix urged consumers to update software relating to actively-exploited zero-day vulnerabilities CVE-2023-6548 and CVE-2023-6549.
  • An article published on January 14, 2024, in dark web forum xss. provides instructions on how CVE-2023-4966 can be exploited, with its reception being indicative of a continued interest amongst threat actors.

Tags: tlp:clear,  dark web,  vulnerability/exploit,  threat actor