Citrix today said it doesn’t expect to patch a particularly nasty bug that could hit more than 25,000 servers until later this month.

The vulnerability in the Citrix Application Delivery Controller (ADC) and Citrix Gateway, initially reported in December, could allow an attacker to access private enterprise networks without authentication. It essentially affects all versions of these Citrix products from 10.5 to 13.0

“We are currently working to develop permanent fixes,” wrote Fermin J. Serna, Citrix chief information security officer, in a blog post published this morning. “As with any product of this nature, and consistent with our policies and procedures, these fixes need to be comprehensive and thoroughly tested.”

The SD-WAN vendor said it expects to roll out patches between Jan. 20 and Jan. 31.

Meanwhile more than 25,000 Citrix servers remain vulnerable to the bug, CVE-2019-19781, according to researchers at Bad Packets. Most of these servers are located in the United States (9,880), German (2,510), and the United Kingdom (2,028), with the most vulnerable endpoints located in the United States. They include military and government systems, schools, hospitals and health care providers, utilities, financial institutions, and “numerous Fortune 500 companies,” according to threat researchers.

“Given the ongoing scanning activity detected by security researcher Kevin Beaumont and SANS ISC since January 8, 2020 — it’s likely attackers have enumerated all publicly accessible Citrix ADC and Citrix (NetScaler) Gateway endpoints vulnerable to CVE-2019-19781,” according to a Jan. 12 Bad Packets blog post. Beaumont dubbed the flaw “Shitrix.”

Over the weekend a group called Project Zero India released a proof-of-concept (PoC) exploit code for this vulnerability on Github. Shortly after that, security research group TrustedSec released another PoC exploit.

“So this is in the wild, active exploitation starting up,” Beaumont tweeted.