← volver al portal

Attackers Exploit Critical Citrix NetScaler Flaw to Create Superuser Accounts and Deploy Disguised Web Shells

LevelBlue's Threat Hunt Operations & Research team identified active exploitation of a critical pre-authentication command injection vulnerability…

IT and security teams should prioritize patching Citrix NetScaler ADC and NetScaler Gateway to the latest available versions immediately. Audit all instances for suspicious user accounts, web shells in CSS-like paths, and unauthorized configuration changes. Monitor access logs for pre-authentication command injection attempts and anomalous activity patterns.