
Citrix ShareFile and NetScaler Vulnerabilities Exploited in Mass Campaign
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical vulnerability in Citrix ShareFile, a secure file transfer solution. Tracked as CVE-2023-24489, the flaw allows unauthenticated attackers to compromise customer-managed storage zones. Cybersecurity firm AssetNote discovered the vulnerability and disclosed it to Citrix. Threat actors have already begun exploiting the flaw, prompting CISA to add it to its catalog of known exploited vulnerabilities. While no public exploitation or data theft has been reported, CISA has mandated that Federal Civilian Executive Branch agencies apply patches by September 6th, 2023. Organizations are advised to update their systems promptly.