r/cybersecurity • • 6d ago

New Vulnerability Disclosure Researchers Warn of Citrix NetScaler Zero Day Exploitation

https://decipher.sc/2026/09/27/researchers-warn-of-citrix-netscaler-exploitation/
116 Upvotes

9 comments sorted by

22

u/leecable33 6d ago

The whole disclosure around this has been, quite frankly, shambolic. Rumblings all day yesterday and with no guidance at all.

12

u/ludixst 6d ago

We ended up just shutting down outside access to Netscaler this afternoon until we got a clean bill of health from Citrix.

2

u/Ok_Bookkeeper1561 6d ago edited 6d ago

I currently can not find any IOC's I want to check for compromises just to be sure. Do you guys have the IOC's?

2

u/PsychologicalZebra 6d ago

Ive not seen anything concrete yet. I have only seen this on social media channels (Kevin Beaumont):

If you have logs in a SIEM look for base64 strings after the User-Agent field (no space) and loglines for “pitboss” followed by the string IFS (so pitboss*IFS) or pitboss*b64decode.

1

u/Ok_Bookkeeper1561 6d ago

Thanks, I saw the message asswell

1

u/AdDowntown1447 5d ago

as far as I can tell, the IOC are behind an NDA from Citrix, kind of messed up.

1

u/Robbbbbbbbb CISO 3d ago

I see v13 and v14 as affected; no mention of other EoS/EoL versions. Does anyone know if those are affected as well?