Hackers are taking advantage of Citrix vulnerabilities
Hackers discovered targeting corporate networks impacted by Citrix vulnerabilities

Savvy hackers have been crawling the web in an attempt to target corporate networks impacted by the recently disclosed vulnerabilities in Citrix systems.
Earlier this month, Citrix announced it discovered multiple vulnerabilities in Citrix ADC, Citrix Gateway and Citrix SD-WAN WANOP appliance models 4000-WO, 4100-WO, 5000-WO and 5100-WO.
Shortly after the announcement was made, hackers attempted to exploit the vulnerabilities to gain access to Citrix’s application delivery controller systems. To do so, hackers exploited the vulnerabilities of CVE-2020-8195 and CVE-2020-8196 in Citrix ADC, Citrix Gateway and Citrix SD-WAN WANOP.
Johannes Ullrich, head of research at the SANS Technology Institute, used a honey pot setup to track hackers taking advantage of the Citrix vulnerabilities.
“As of today, my F5 honeypot is getting hit by attempts to exploit two of the Citrix vulnerabilities disclosed this week,” Ullrich said in a post published by the SANS Technology Institute.
“It is not clear exactly which CVE was assigned to which vulnerability, but the possible candidates are CVE-2020-8195, CVE-2020-8196,” he continued.
According to Ullrich, hackers used the vulnerabilities for arbitrary file downloads and to retrieve PCI-DSS reports from Citrix.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Citrix has since patched the vulnerabilities identified in its Citrix ADC, Citrix Gateway, and Citrix SD-WAN WANOP. This included patching CVE-2020-8195 and CVE-2020-8196 as well.
CISO Citrix CISO Fermin J. Serna explained, however: “We are limiting the public disclosure of many of the technical details of the vulnerabilities and the patches to further protect our customers. Across the industry, today’s sophisticated malicious actors are using the details and patches to reverse engineer exploits.
"As such, we are taking steps to advise and help our customers but also do what we can to shield intelligence from malicious actors.”
Several hackers have attempted to target and exploit Citrix ADC in the past few months. In March, reports revealed the state-sponsored APT41 group targeted Citrix NetScaler/ADC, Cisco routers, and Zoho ManageEngine Desktop Central products to attack 75 customers between Jan. 20 and March 11.
Finastra experienced a ransomware attack targeting its Citrix ADC servers in March, exploiting the CVE-2019-1978 vulnerability as a potential attack vector.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Citrix Bleed an “early Christmas present” for hackers as flaw claims latest victim
News Xfinity is the latest firm to fall victim to the Citrix Bleed vulnerability
By George Fitzmaurice Published
-
Citrix Bleed remains out of control with thousands of appliances still vulnerable
News Thousands of organizations at risk of Citrix Bleed have still not patched, analysis suggests
By Ross Kelly Published
-
What is Citrix Bleed and should you be worried?
News A critical buffer over-read can expose sensitive information in affected devices
By Rory Bathgate Published
-
Patch-resistant autonomous exploits of Citrix NetScaler hardware hit thousands in Europe
News More than 1,800 Citrix NetScaler devices still contained backdoors at the time of publication
By Rory Bathgate Published
-
Citrix discloses critical NetScaler Gateway vulnerability
News Users of affected products have been urged to implement patches immediately to mitigate risk
By Ross Kelly Published
-
Citrix patches XenMobile vulnerability
News Positive Technologies spots serious flaw in Citrix XenMobile
By Nicole Kobie Published
-
Citrix Synergy 2019: One year on GDPR is shaping the role of privacy in brand survival
In-depth Despite big fines levied, Citrix’s privacy chief says we still don’t have a sense of what enforcement will look like
By Keumars Afifi-Sabet Published
-
Security takes pride of place at Citrix Synergy 2017
News ‘Software-defined perimeter’ will help organisations ensure the security of their networks
By Jane McCallion Published