Authorities warned that critical vulnerabilities in Veeam ONE and Citrix NetScaler Gateway/ADC could let attackers execute arbitrary commands, bypass security controls, and gain elevated privileges on exposed systems. The flaws were described as severe because successful exploitation could allow an intruder to operate on a target like a legitimate user and, in some cases, download and run additional programs over the network.
The alerts said exploitation could also expose confidential information and, in the Citrix case, enable unauthorized modification of data such as web content. Security bypass was highlighted as a path to reaching otherwise protected internal networks, while privilege escalation could hand attackers administrator-level access, increasing the risk of broader compromise and data theft.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Critical vulnerabilities in Veeam ONE were publicly reported. The flaws were described as potentially allowing arbitrary command execution, security bypass, privilege escalation, and unauthorized access to confidential information.
A critical vulnerability affecting Citrix NetScaler Gateway and ADC software was publicly reported. The issue was described as enabling severe impacts including arbitrary command execution, security bypass, privilege escalation, unauthorized data modification, and disclosure of confidential information.
A critical vulnerability affecting Citrix Gateway and Citrix ADC products was publicly reported. The issue was described as enabling arbitrary command execution, security bypass, privilege escalation, unauthorized data modification, and disclosure of confidential information.
A critical vulnerability in Adobe Acrobat and Reader was publicly reported. The flaw was described as enabling arbitrary command execution, potentially allowing an attacker to use the affected system with the privileges of the current user and run additional programs.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.