logo

CISA pushes federal agencies to patch Citrix RCE within a week

ID: bf01ce74-a60a-5f70-9c1f-527d28974629

STIX ID: report--bf01ce74-a60a-5f70-9c1f-527d28974629

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-01-17

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA added three actively exploited zero-day vulnerabilities — Citrix NetScaler CVE-2023-6548 (code injection/RCE), CVE-2023-6549 (buffer overflow), and Chromium V8 CVE-2024-0519 — to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to patch them (CVE-2023-6548 within one week, the others within three weeks); the advisory notes active exploitation, guidance to block or update exposed NetScaler appliances, and that tens of thousands of NetScaler devices remain Internet-accessible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.