The Cybersecurity and Infrastructure Security Agency has issued an urgent alert about critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that attackers are actively exploiting. Banks are being asked to take immediate action to protect their systems.
Citrix provides technology that organizations use to deliver applications and enable remote access to their systems. Its NetScaler products often sit at the entrance to an organization’s network, managing connections between outside users and internal applications. The vulnerabilities exploit flaws in how affected devices process incoming data, allowing attackers to run malicious commands without a valid username or password — and without an employee clicking a link or taking any other action. Citrix said the vulnerabilities were discovered using artificial intelligence.
To address the potential effects for the banking sector, the American Bankers Association engaged with the Financial Services Sector Coordinating Council, which coordinates industry efforts to protect financial infrastructure, and the Financial and Banking Information Infrastructure Committee, which coordinates financial regulators’ efforts to strengthen sector resilience. ABA also participated in a Core Executive Response Group call to assess potential impacts and coordinate the sector’s response.
Banks should immediately identify affected systems, apply the updates outlined in the Citrix security bulletin, and investigate whether attackers gained access before the updates were installed, according to CISA and the other agencies. Patching addresses the vulnerability but does not, by itself, remove an attacker who may already have established access.
In addition, banks should assess their exposure through technology providers even if they do not use NetScaler themselves. Banks should directly contact their managed IT providers, core processors, hosted application providers, and other vendors that hold bank data or have access to bank systems to determine whether they use affected products.









