Security experts say tens of thousands of organizations are at risk from the flaw, first disclosed last month. A group calling itself Project Zero India has released proof-of-concept exploit code for the vulnerability. The directory traversal flaw exists in Citrixs Application Delivery Controller and Gateway. The flaw was discovered by Mikhail Klyuchnikov, a researcher at London-based vulnerability assessment firm Positive Technologies. The U.S. National Security Agency’s Rob Joyce, who’s the senior adviser for cybersecurity strategy to the director, says the vulnerability is a “doozie””]