The directive, announced on Thursday, targets a vulnerability in Citrix NetScaler Application Delivery Controller (ADC) and Gateway products that allows an unauthenticated attacker to execute arbitrary code remotely. While CISA has not disclosed specific attack details, the agency noted that the flaw is being actively exploited, raising the urgency for federal networks.
CISA's Binding Operational Directive 22-01, established in 2021, mandates that federal agencies rapidly remediate known exploited vulnerabilities. The directive requires agencies to either apply the vendor-supplied patch or implement approved compensating controls within a specified timeline. Failure to comply can lead to escalating enforcement actions, including possible referral to the Office of Management and Budget and the Department of Homeland Security.
The vulnerability affects multiple versions of Citrix NetScaler ADC and Gateway. Citrix has released security updates to address the flaw, and CISA strongly encourages all organizations—not just federal agencies—to apply the patches immediately. Given that Citrix products are widely deployed in enterprise and cloud environments, the potential for widespread compromise is significant.
Cybersecurity experts warn that adversaries are likely scanning for unpatched systems and may already be exploiting the flaw to gain initial access to networks. The rushed patch timeline underscores the severity of the threat. Agencies must balance the need for rapid remediation with operational continuity, as patching critical infrastructure can cause downtime if not carefully managed.
The directive comes amid a broader push by CISA to reduce the window between vulnerability disclosure and exploitation. The agency maintains a catalog of known exploited vulnerabilities that serves as a reference for both government and private sector organizations. This particular Citrix flaw was added to that catalog upon issuance of the directive.