Hackers are actively exploiting dual Citrix NetScaler zero-days right now. If you think your perimeter firewall or standard Web Application Firewall is protecting your Citrix ADC and Gateway appliances, you're making a critical mistake.
Threat actors are bypassing standard perimeter inspections using unauthenticated remote code execution vulnerabilities under active, in-the-wild attack. The prevailing wisdom in many IT departments is to wait for the weekend change window to patch. Or they assume a simple device reboot will clear any hostile payload. Honestly, that's just wishful thinking. These exploits execute directly in memory. They establish stealth persistence that survives reboots, handing attackers root access to pivot straight into your internal network before sunrise.
Here are three hard truths and immediate triage actions your SOC and incident response teams must execute today.
First, don't rely on standard access logs to spot this attack. This is an unauthenticated remote code execution exploit targeting the underlying packet processing engine, so standard HTTP request logs often miss the payload entirely. Hunt for memory corruption signatures instead. Check the var crash directory for newly generated core dump files. Inspect your ns log for abnormal segmentation faults and killed worker processes. If you see recurring crashes in the nsppe daemon paired with anomalous inbound POST requests, you're already dealing with an active compromise attempt.
Second, stop assuming a reboot clears the adversary. The biggest misconception in network appliance security is that memory-only exploits disappear upon restart. Attackers exploit the NetScaler ADC architecture by modifying startup routines right away. They drop stealth backdoors into the flash nsconfig directory and cron tables. When you reboot without forensic imaging, you destroy volatile memory artifacts while executing their persistent scripts on startup. Audit your cron files. Check for unauthorized shell binaries in var and flash. Verify file integrity against known clean builds.
Third, mitigate right now without taking down your production services. You don't need catastrophic business downtime to protect your environment. Restrict access to the NetScaler management IP and internal RPC ports immediately so they're never exposed to untrusted subnets. Implement granular responder policies to drop malformed header patterns at the appliance boundary. Isolate external-facing Gateway VIPs into dedicated segmentation zones. Run automated threat hunting queries across your firewall logs for outbound lateral beaconing.
Don't wait for a scheduled change freeze or a third-party breach alert. Audit your Citrix NetScaler fleet right now. Verify your var crash directories, lock down your management interfaces, and share this protocol with your incident response team immediately.