Skip to content
Threat Feed
high advisory

Remote Code Execution Vulnerabilities in NetScaler ADC and Gateway

Multiple vulnerabilities discovered in NetScaler ADC and NetScaler Gateway may allow an unauthenticated remote attacker to execute arbitrary commands, potentially leading to full appliance compromise.

Multiple vulnerabilities have been identified within NetScaler ADC and NetScaler Gateway products, developed by Cloud Software Group. These appliances are widely deployed for application delivery optimization and secure remote access. The most significant of these flaws permits an unauthenticated remote attacker to achieve remote code execution (RCE) on the underlying system. Successful exploitation allows for the execution of arbitrary commands, granting the attacker control over the appliance. Given the role these devices play in network security and remote access, compromise provides a critical beachhead for deeper lateral movement and interception of encrypted traffic or user credentials. Defenders should prioritize auditing internet-facing NetScaler instances and preparing for rapid deployment of vendor-supplied patches as they become available.

Impact

Successful exploitation of these vulnerabilities leads to full system compromise of the NetScaler ADC or Gateway appliance. This could result in unauthorized access to sensitive application data, interception of user traffic, potential exfiltration of authentication tokens, and the ability to pivot into protected internal segments of the network. The scope affects all organizations utilizing these products for load balancing and secure remote access.

Recommendation

  • Identify all internet-facing NetScaler ADC and NetScaler Gateway instances within the infrastructure.
  • Monitor logs for unusual outbound connections or unexpected process execution originating from the NetScaler management interface.
  • Apply security patches immediately once released by Cloud Software Group.
  • Restrict access to the NetScaler management interface to trusted, internal IP ranges to reduce the attack surface for remote exploitation attempts.

Immediate actions

Inventory all internet-facing NetScaler ADC and Gateway instances.

IT Operations 24h

Enrichment needed

  • Specific CVE IDs and patch versions. (CTI) Necessary for identifying vulnerable software versions and applying specific remediation.

Mitigations

Apply vendor patches as soon as they are published by Cloud Software Group.

immediate IT Operations

RCE vulnerabilities in NetScaler products