Citrix NetScaler again: two exploited zero-days, and why patching is only half the job
Two critical flaws in Citrix NetScaler ADC and Gateway are being exploited in the wild, both scored 9.5, both reachable by an unauthenticated attacker on the internet-facing side of the box. CISA has given federal agencies until 30 September. Here is what the flaws are, why the honest instruction from several national authorities is to take the appliance offline, and why installing the update does not, on its own, get an intruder out.