Unpatched Citrix NetScaler Zero-Days: What To Do Now

What happened
On September 26, security research firm watchTowr reported that two previously unknown vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances are being exploited in the wild. Both reportedly allow remote code execution, meaning an attacker who can reach the appliance over the network may be able to run their own code on it. The reporting was picked up via feeds.feedburner.com.
As of that reporting, Citrix had not confirmed the flaws or shipped a fix, and there is no patch to install. Some administrators have reportedly pulled their appliances offline rather than sit exposed while waiting. We are not going to speculate beyond that: affected version ranges, CVE numbers, and indicators of compromise were not established in the reporting we have seen, so those are items to verify directly with Citrix advisories and your appliance vendor or integrator rather than assume.

Why this matters for the audience
NetScaler gear sits in a specific, uncomfortable spot: it is the front door. These appliances typically terminate VPN and remote-desktop gateway traffic, publish internal applications to the internet, and load-balance line-of-business systems. That means the device is reachable from anywhere by design, it often holds session tokens and credentials, and it usually sits at or near the network edge with broad internal visibility. A remote code execution flaw in that position is not a nuisance, it is an initial-access problem, and initial access is what ransomware crews buy.
For Pittsburgh-area businesses in the 10 to 200 employee range, the practical risk profile looks like this. Law firms and CPA practices that stood up remote access during tax season or trial prep and never revisited the architecture may be running an appliance nobody has logged into in a year. Healthcare organizations publishing EHR or imaging access through a gateway have both a HIPAA Security Rule obligation to manage known vulnerabilities and a breach-notification clock waiting on the other side of an incident. Financial services firms under the FTC Safeguards Rule are expected to have a documented process for exactly this scenario, including an incident response plan they can actually execute.
Defense contractors and manufacturers in the supply chain around Pittsburgh have the sharpest exposure. If controlled unclassified information is reachable through a remote-access path, a compromise of that path is a reportable cyber incident under DFARS 7012 obligations, with a 72-hour reporting window to DoD, and it undercuts the vulnerability-management and boundary-protection practices your CMMC assessment depends on. Also worth naming: appliances like this are frequently inherited. They were installed by a previous provider or a one-off project, they are not in anyone's patch cycle, and no one owns them. If that describes any device in your environment, this week is a good week to find out.
What to do about it
Start here, in order, and do not wait for a patch announcement to begin.
- Confirm whether you run this gear at all. Check your asset inventory for NetScaler ADC or NetScaler Gateway, including virtual appliances in a data center or cloud tenant. If you do not maintain a current inventory of internet-facing devices, that gap is the real finding, and it will come up in any SOC 2 or HIPAA review.
- Decide on temporary exposure reduction today. If you have an affected appliance, evaluate taking the management interface and, where the business can tolerate it, the public-facing service offline or restricting access to a known IP allowlist until Citrix publishes guidance. Weigh the operational hit honestly, but make it a decision, not a default.
- Verify vendor guidance directly. Subscribe to Citrix security bulletins and check for an official advisory, affected build list, and any interim mitigation. Treat third-party write-ups as early warning, not as configuration instructions.
- Hunt for signs of access, assuming you cannot patch. Pull appliance logs, authentication records, and configuration change history. Look for unexpected admin logins, new accounts, altered config, odd outbound connections, and VPN sessions from unfamiliar geographies. Make sure those logs ship somewhere off the device, because an attacker with code execution can clean up after themselves locally.
- Invalidate sessions and rotate credentials on the appliance. Terminate active sessions, rotate local admin passwords and any service accounts the appliance uses, and confirm multifactor authentication is enforced on every remote-access path. Session-token theft is a recurring theme in edge-device compromises.
- Confirm your detection and containment coverage inland. Verify that endpoints and servers behind the appliance are reporting to EDR or MDR and that someone is watching alerts after hours. The goal is catching lateral movement even if the edge gives way.
- Dust off the incident response plan and know your clocks. For regulated firms, write down now who calls counsel, who notifies clients, and what your reporting deadlines are. If you are a defense contractor, that 72-hour DoD reporting requirement is not something to research mid-incident.
If your team cannot complete steps one and two by Friday, that is a capacity signal worth raising at your next technology roadmap review.

How we help
PGH Networks manages the unglamorous work this situation depends on: a real asset inventory, disciplined patch management and firmware cycles, hardened remote-access architecture, monitored detection and response, and documented evidence that satisfies HIPAA, SOC 2, FTC Safeguards, and CMMC Level 2 auditors. We also handle the identity and conditional-access side in Microsoft 365, which is often the better long-term answer than keeping a legacy edge appliance in the critical path. If you are not certain whether you run affected hardware, we will help you find out.
Talk to us
Call 724.888.7007 or reach us through the contact form and we will scope a remote-access exposure review for your environment this week.
Related reading

ClickFix Fake CAPTCHAs Are Tricking Office Users Into Self-Infecting
A new CTM360 report maps 17,000 ClickFix URLs. Here is what Pittsburgh SMBs in legal, CPA, healthcare and defense work should verify and train on now.

Chrome and Windows Zero-Day Chain: What Pittsburgh SMBs Should Do Now
A Chinese threat actor chained Chrome and Windows zero-days via fake websites. Here is what Pittsburgh small and mid-sized businesses should verify and patch now.

Fake LastPass Installer Kills EDR With a Signed Driver
A fake LastPass Authenticator installer uses a Microsoft-signed driver to disable antivirus and EDR. What Pittsburgh SMBs should verify and fix this week.