CitrixBleed 2, a vulnerability in Citrix NetScaler ADC and NetScaler Gateway, is actively being exploited in the wild by threat actors.
The flaw allows hijacking user sessions and access to environments. Security researchers warn that the majority of instances remain unpatched.
WatchTowr Labs found a significant portion of users had not patched against CitrixBleed 2, urging immediate action as exploitation is ongoing.
Citrix is redirecting media inquiries to a blog post stating there is currently no evidence of exploitation, but also stresses the importance of immediate updates due to active exploitation.