The Cybersecurity and Infrastructure Security Agency (CISA) recently released a security advisory that indicates that threat actors have been exploiting a Zero-day vulnerability in Citrix ADC (Application Delivery Controller) and NetScaler Gateways.
A vulnerability was discovered that enabled the placement of a webshell on a non-production environment of a critical infrastructure organization. This was reported to CISA and Citrix Systems.
Threat actors exploited an unauthenticated, remote code execution vulnerability to drop these webshells on the environment and also attempted to laterally move to the domain controller. However, it was blocked due to network-segmentation controls.
This vulnerability can be exploited by a threat actor if the appliance is configured as a Gateway (VPN Virtual Server, RDP proxy etc.,) or Authentication, Authorization and Auditing (AAA) Server. The CVSS Score for this vulnerability is given as 9.8 (Critical).
Citrix systems has released patches for fixing this vulnerability.
Threat actors uploaded a malicious TGZ file on the ADC appliance, which consisted of setuid binary, generic webshell and discovery script for conducting an SMB scan on the ADC. Furthermore, AD enumeration and data exfiltration were performed with the webshell. Additional activities performed by the threat actors include,
Other queries by the threat actors were unsuccessful as the organization implemented a segmented environment for the ADC appliance. The exfiltration queries that failed are as follows
Nevertheless, the threat actors also deleted the authorization config file /etc/auth.conf to prevent privileged users from logging in remotely. If an attempt by the organization was made to regain access to the server by rebooting into single user mode, it would delete the threat actors’ artifacts.
CISA has released a complete report about the MITRE ATT&CK framework, detection methods, mitigation and prevention steps. It is recommended for organizations to follow them and mitigate these kinds of breaches by threat actors.
Four security flaws described in the supplied Apache Struts advisories could expose affected applications to…
A former infrastructure engineer has been sentenced to 32 months in federal prison for sabotaging…
A new GitHub Copilot CLI finding that could allow an attacker-controlled web page to guide…
Every function in a security operations center, from alert triage to incident response, depends on…
ASOS is investigating a cyber incident after customers received an unauthorized app notification claiming hackers…
Silver Springs, United States / Maryland, October 6th, 2026, CyberNewswire Aembit, the identity control plane…