Citrix released permanent patches for the critical CVE-2019-19781 vulnerability affecting Citrix Application Delivery Controller (ADC), formerly NetScaler ADC, and Citrix Gateway appliances. Initial fixes for versions 11.1 and 12.0 were issued on 19 January 2020, followed by final patches for versions 10.5, 12.1, and 13.0 on 23–24 January. Successful exploitation could give an unauthenticated attacker full control of an affected Citrix server and potentially provide access to connected networks.
The Dutch National Cyber Security Centre urged organizations to patch according to their risk assessments, continuously monitor for exploitation, and review logs dating to 17 December 2019. Organizations that had not applied mitigations before 9 January were advised to presume compromise. Where patching was not immediately possible, the NCSC recommended restricting access through IP allowlisting, deploying a web application firewall, requiring client certificates, or taking exposed systems offline; changing an external service port was characterized only as a discovery deterrent, not an effective fix.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Citrix made patches available for affected NetScaler ADC and Gateway Server versions 11.1 and 12.0.
The NCSC updated its guidance for organizations unable to upgrade internet-accessible Citrix servers, recommending measures including IP allowlisting, web application firewalls, client-certificate authentication, and changing exposed service ports.
The Dutch National Cyber Security Centre published its initial notice advising organizations on protective measures for affected Citrix systems.
Citrix released patches for affected versions 10.5, 12.1, and 13.0 over 23–24 January, completing availability of fixes cited by the NCSC.
Citrix published information about the Citrix ADC and Gateway Server vulnerability, initiating the period of log review later recommended by the Dutch NCSC.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
ncsc.nl
Open sourcencsc.nl
Open sourcecitrix.com
Open sourcecitrix.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.