Skip to main content

Share story

Security Policy

CISA Orders Federal Agencies to Patch Actively Exploited Citrix NetScaler Flaw by Thursday

CISA Orders Federal Agencies to Patch Actively Exploited Citrix NetScaler Flaw by Thursday Image: Primary
The Cybersecurity and Infrastructure Security Agency has ordered all U.S. federal civilian agencies to apply patches for the critical Citrix NetScaler vulnerability being actively exploited in the wild, setting a Thursday deadline for compliance, according to a report by BleepingComputer. CISA added the Citrix flaw to its Known Exploited Vulnerabilities catalog, triggering the mandatory patching requirement under Binding Operational Directive 22-01, which requires federal civilian executive branch agencies to remediate catalogued vulnerabilities within defined timeframes. The Thursday deadline is among the shortest CISA has issued, reflecting the severity of active exploitation activity. The vulnerability is a memory-related flaw in Citrix NetScaler ADC and NetScaler Gateway, products that handle authentication, load balancing, and SSL inspection for enterprise networks. The products are widely deployed across federal agencies as well as financial services, healthcare, and critical infrastructure operators, making unpatched systems a high-value target for threat actors. The CISA directive applies formally only to federal civilian agencies, but the agency strongly encourages private sector organizations to treat catalogued vulnerabilities as high priority given the documented exploitation activity. Ransomware groups and nation-state actors routinely scan for unpatched Citrix systems given the product's history as a high-impact entry point. Citrix, now part of Cloud Software Group, has published a security bulletin with affected version numbers and patch details. The prior Citrix Bleed vulnerability in 2023 was exploited by the LockBit ransomware group to compromise Boeing, Allen and Overy, and the Industrial and Commercial Bank of China before patches were widely applied. Organizations that cannot patch immediately were advised to restrict access to the affected product from untrusted networks as a temporary mitigation.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Infrastructure
Security Infrastructure

Two unpatched NetScaler flaws reportedly exploited in attacks

Security firm watchTowr says attackers have exploited two previously undisclosed flaws that could allow remote code execution on Citrix NetScaler appliances. The firm said it identified the flaws during forensic investigations and...

Products Capital
Products Capital

Numeral raises $100M for sales tax automation

Numeral raised a $100M Series C led by Insight Partners, FinTech Global reported. Its AI-powered platform automates sales tax compliance workflows in over 90 countries. The financing adds capital to a business serving companies t...

Capital Products
Capital Products

HIFI raises $37M for stablecoin payment infrastructure

HIFI raised a $37M Series A led by Left Lane Capital, The Block reported. The New York City company provides software interfaces for stablecoin payments and settlements, giving businesses a way to connect those transactions to the...

Infrastructure Capital
Infrastructure Capital

PicoJool raises $27.5M for AI data center interconnects

PicoJool raised a $27.5M Series A led by Socratic Partners, SiliconANGLE reported. The startup is developing interconnects for AI data centers based on vertical cavity surface emitting lasers. Former Intel chief executive Pat Gel...

Robotics Products
Robotics Products

Volkswagen weighs exit from robotaxi business Moia

Volkswagen intends to explore options for exiting its Moia robotaxi business by the end of 2026, including a sale to investors or liquidation, Heise reported, citing Wirtschaftswoche's account of an internal strategy paper. The re...