<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Citrix-Netscaler on CuraSec</title><link>https://curasec.metacog.co.kr/tags/citrix-netscaler/</link><description>Recent content in Citrix-Netscaler on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 27 Aug 2026 21:01:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/citrix-netscaler/index.xml" rel="self" type="application/rss+xml"/><item><title>CISA KEV: Citrix NetScaler RCE Actively Exploited, Feds Must Patch by Saturday</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-cisa-orders-feds-to-patch-citrix-netscaler-rce-flaw-by-satur/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-cisa-orders-feds-to-patch-citrix-netscaler-rce-flaw-by-satur/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Citrix NetScaler is a common edge appliance; active exploitation of an RCE with a CISA KEV order makes this immediate. Identify all NetScaler instances in your environment and apply the vendor patch now — Saturday deadline applies to federal agencies but exploitation is not sector-limited.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of an edge RCE means attackers may already be inside before patching occurs; initiate an assume-breach sweep on NetScaler appliances, reviewing management-plane logs and lateral movement indicators since the vulnerability became public.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> CISA&amp;rsquo;s mandatory patch order with a Saturday deadline signals systemic exploitation — confirm whether your organization runs Citrix NetScaler, verify remediation is in progress, and brief leadership if you operate federal systems or customer-facing NetScaler infrastructure.&lt;/li>
&lt;/ul></description></item><item><title>CISA KEV: Six Actively Exploited Flaws — NetScaler, Linux, SQL Server</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-cisa-adds-six-exploited-flaws-to-kev-including-netscaler-lin/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-cisa-adds-six-exploited-flaws-to-kev-including-netscaler-lin/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CISA KEV listing with active exploitation across NetScaler ADC/Gateway, Linux, and SQL Server — all plausible in enterprise environments; patch affected NetScaler and SQL Server instances immediately and verify Linux kernel versions against the KEV entries.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> NetScaler edge devices are a prime assume-breach target when exploitation precedes patching; hunt for post-exploitation activity on NetScaler appliances and any lateral movement from SQL Server hosts since these vulnerabilities entered active exploitation.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Six KEV additions spanning widely-deployed infrastructure signal a broad active-exploitation wave; confirm your engineering teams are tracking patch timelines for NetScaler, Linux, and SQL Server against CISA&amp;rsquo;s binding operational directive deadlines.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2019-1068 — CISA KEV: listed, EPSS 0.53, public PoC on GitHub&lt;/li>
&lt;/ul></description></item></channel></rss>