Hundreds of Citrix NetScaler ADC and Gateway servers breached, exploiting a critical code injection vulnerability

In a concerning development for cybersecurity, hundreds of Citrix NetScaler ADC and Gateway servers have fallen victim to malicious actors who exploited a critical code injection vulnerability. Referred to as CVE-2023-3519, this flaw could potentially lead to unauthenticated remote code execution.

Details of the vulnerability

The code injection vulnerability, which Citrix addressed through a patch last month, carries a CVSS score of 9.8. This high score underscores the severity and potential impact of the flaw. Such a vulnerability can expose organizations to significant risks and leave them vulnerable to cyberattacks.

Scope of the breach

The reach of this breach spans across several countries. The largest number of impacted IP addresses is found in Germany, followed by France, Switzerland, Italy, Sweden, Spain, Japan, China, Austria, and Brazil. This highlights the global impact of the vulnerability and the need for organizations worldwide to remain vigilant in their cybersecurity efforts.

Previous disclosures

The exploitation of CVE-2023-3519 to deploy web shells was previously disclosed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). This highlights the importance of promptly addressing and mitigating such vulnerabilities by organizations to prevent unauthorized access and potential data breaches.

Discovery of an Additional Flaw

In addition to the CVE-2023-3519 exploit, another critical flaw in Citrix ShareFile software, known as CVE-2023-24489, was recently detected. GreyNoise, a cybersecurity firm, reported three IP addresses attempting to exploit this vulnerability. Citrix has promptly addressed the issue in ShareFile storage zones controller version 5.11.24 and subsequent updates.

Technical details of the bug

The bug present in Citrix ShareFile software can be traced back to a simpler version of a padding oracle attack. It has been identified that the default values for AES encryption in .NET are Cipher Block Chaining (CBC) mode and PKCS#7 padding. A potential padding oracle attack can be identified by observing how the system behaves when a different type of padding is provided. This technical insight highlights the complexity of the vulnerability and the importance of strong cybersecurity measures.

These recent breaches of Citrix NetScaler ADC and Gateway servers shed light on the critical need for organizations to promptly patch vulnerabilities and ensure robust cybersecurity measures. The exploitation of the CVE-2023-3519 and CVE-2023-24489 vulnerabilities demonstrates the constant and evolving threats faced by businesses and individuals alike. It is crucial that organizations remain proactive in their approach, regularly updating and patching their systems to prevent unauthorized access and potential data breaches. These incidents serve as a reminder of the ever-present risks and the need for continuous vigilance in safeguarding sensitive information.

Explore more

Is Tower Insurance Facing a Major Ransomware Breach?

Regulatory authorities have been notified as Tower Insurance monitors its network following the unverified listing of the company on a dark web extortion platform. This development has sent ripples through the financial sectors of both New Zealand and Australia, where the insurer maintains significant market presence and public listings on major stock exchanges. While the group behind the leak site

Modernizing Data Protection During the VMware Exit

Traditional server virtualization models frequently outsource core resilience to a secondary protection tier, creating a structural dependency that complicates site-level failover procedures. As organizations navigate the complex landscape of the Broadcom era, the transition away from legacy environments is increasingly viewed as more than a simple vendor replacement. In 2026, the movement known as the VMware Exit has gained significant

How Is Slough Becoming Europe’s Premier Data Center Hub?

Located just 20 miles from London’s financial heart, Slough has quietly surpassed major European cities to become the continent’s most densely concentrated data center cluster. This transformation has turned a town once synonymous with mid-century industrial decay and comedic parody into a vital pillar of the global digital economy. The shift is not merely aesthetic; it represents a fundamental reordering

How to Unlock Professional vGPU Features on Consumer GPUs?

For users running Arch Linux, enabling professional features on a GTX 1050 Ti necessitates blacklisting the Nouveau driver and performing a manual DKMS installation from a TTY interface. This technical hurdle highlights the artificial barriers that manufacturers place between consumer graphics cards and enterprise-grade hardware. While a GeForce card in a standard gaming rig often uses the same silicon as

What Are the Most Critical Cyber Threats in 2026?

Device code phishing has seen a staggering increase of over one thousand percent as attackers exploit login flows designed for devices without keyboards. This shift illustrates a broader trend in the cybersecurity ecosystem of 2026, where the most effective attacks no longer rely on brute force but on the subtle subversion of legitimate business processes. The current landscape is defined