Multiple critical security flaws have been detected recently in the Citrix Application Delivery Controller (ADC), Citrix Gateway, and Citrix SD-WAN WANOP. And without any authentication these critical vulnerabilities allow any threat actor to crash the whole network.
These affected Citrix products are mainly used to secure remote access and for application-aware traffic management.
Here are vulnerabilities that are affecting these Crtitix products:-
All these three Citrix products are widely deployed globally and among them, as of early 2020, the Gateway and ADC alone installed in at least 80,000 companies in 158 countries. In short, it will have a great impact on exploitation due to its mass use.
Here are the supported versions of Citrix ADC and Citrix Gateway that are affected by CVE-2021-22955:-
While in the case of CVE-2021-22956, all the supported versions of Citrix ADC, Citrix Gateway, and Citrix SD-WAN WANOP Edition are affected. And here below we have mentioned all the supported versions of Citrix ADC, Citrix Gateway, and Citrix SD-WAN WANOP Edition that supports the fixed configuration change:-
In case of CVE-2021-22955 vulnerability, users must upgrade to one of the following supported versions of Citrix ADC and Citrix Gateway:-
In case of CVE-2021-22956 vulnerability, users must configure their appliance according to the Citrix Application Delivery Controller, Citrix Gateway, and Citrix SD-WAN WANOP Edition – Management Module Configuration Reference Guide:-
Moreover, Citrix currently is notifying all its users and channel partners about this potential security threat. And they have also assured that the users who are using the Citrix-managed cloud services are still unaffected.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity, and hacking news updates.
The Cybersecurity and Infrastructure Security Agency (CISA) has extended funding to the MITRE Corporation, ensuring…
New vulnerabilities in Windows Task Scheduler's schtasks.exe let attackers bypass UAC, alter metadata, modify event…
A critical vulnerability in Microsoft Windows, identified as CVE-2025-24054, has been actively exploited in the…
Attackers have been deploying server-side phishing schemes to compromise employee and member login portals across…
CloudSEK's Security Research team, a sophisticated cyberattack leveraging malicious online PDF converters has been demonstrated…
The Interlock ransomware intrusion set has escalated its operations across North America and Europe with…