CVE-2023-3519Active Exploitation(citrix / netscaler_application_delivery_controller)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch citrix netscaler_application_delivery_controller systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Unauthenticated remote code execution

4.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-08-09. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netscaler_application_delivery_controller
  • netscaler_gateway

Threat summary

  • Active exploitation appears in 5 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 5 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 4 classified signals
  • Peaked 10d ago at 1 mentions (2026-02-18); latest day: 1
  • 11 total mentions across 11 days

Affected systems

Vendors
Products
netscaler_application_delivery_controllernetscaler_gateway

Deep dive

Activity timeline11 mentions / 11d
00111Mentions · 2026-02-18: 1Mentions · 2026-02-19: 1Mentions · 2026-03-12: 1Mentions · 2026-03-16: 1Mentions · 2026-04-15: 1Mentions · 2026-04-29: 1Mentions · 2026-06-15: 1Mentions · 2026-06-18: 1Mentions · 2026-08-23: 1Mentions · 2026-09-28: 1Mentions · 2026-10-04: 1Active Exploitation · 2026-02-18: 1Active Exploitation · 2026-02-19: 1Active Exploitation · 2026-03-12: 1Active Exploitation · 2026-06-15: 1Active Exploitation · 2026-06-18: 1Patch / Workaround · 2026-08-23: 1Technical Details · 2026-08-23: 102-1802-1903-1203-1604-1504-2906-1506-1808-2309-2810-04
Signal classification2 categories
Active Exploitation
555.6%
General
444.4%
Referenced assets17 URLs
Classification over time
DateTotalLabels
2026-02-181
Active Exploitation1
2026-02-191
Active Exploitation1
2026-03-121
Active Exploitation1
2026-03-161
General1
2026-04-151
General1
2026-04-291
General1
2026-06-151
Active Exploitation1
2026-06-181
Active Exploitation1
2026-08-231
General1
Full discourse11 posts
  • Dark Web Informer@DarkWebInformer

    citrixInspector: Passively identify Citrix ADC / NetScaler ADC & Gateway builds and check for known vulnerabilities, including CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and KEV-listed CVE-2026-88771/88772. GitHub: https://github.com/securekomodo/citrixInspector https://t.co/UXQoHjAzb4

    2140594410.8K
    242.2K followersView on X
  • Cheena@simpleCheena

    Another day, another NetScaler zero-day burned in the wild. SAML flaws are the gift that keeps giving — identity is the new perimeter, and it's leaking. 🎁🔥 How many orgs still haven't patched CVE-2023-3519? The exploit chain is already weaponized.

    2101055
    115 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    @briancheong Absolutely, Brian. With CVE-2023-3519 exposing vulnerabilities in misconfigured MCPs, adopting strict allowlists and sandboxes isn’t just a strategy; it's a survival imperative in tightening security paradigms. Every tool input could ind...

    Post summary

    The tweet mentions CVE-2023-3519 and urges stricter security controls but provides no concrete technical, exploit, or remediation details.

    0001074
    129 followersView on X
  • RST Cloud@rst_cloud
    General

    #threatreport #HighCompleteness VEEAM UNDER FIRE: Understanding CVE-2026–44963 & Ransomware Group Exploit Claims | 20-08-2026 Source: https://theravenfile.com/2026/08/20/veeam-under-fire-understanding-cve-2026-44963-ransomware-group-exploit-claims/ Key details below ↓ 🧑‍💻Actors/Campaigns: Lynx_ransomware Carbanak Dragonforce Vice_society Lazarus Bluenoroff Warlock Hunters_international Teampcp 💀Threats: Lynx, Akira_ransomware, Fog_ransomware, Credential_harvesting_technique, Credential_dumping_technique, Qilin_ransomware, Rclone_tool, Conti, Blackbasta, Kerberoasting_technique, Bitsadmin_tool, Pdq_deploy_tool, Cuba_ransomware, Cobalt_strike_tool, Bughatch, Burntcigar, Metasploit_tool, Defendercontrol_tool, Veeamhax, Anydesk_tool, Simplehelp_tool, Medusa_ransomware, Clop, Lemurloot, Rhysida, Secretsdump_tool, Putty_tool, Nltest_tool, Ransomhub, Lockbit, Dcsync_technique, Gentlekiller, Av-killer, Hexkiller, Throttleblood, Havockiller, Oxideharvest, Impacket_tool, Wmiexec_tool, Netexec_tool, Inc_ransomware, Anubis, Dire_wolf, Wevtutil_tool, Shadow_copies_delete_technique, Vssadmin_tool, Everest_ransomware, Supply_chain_technique, 🎯Victims: Data backup and recovery sector 🏭Industry: Critical_infrastructure 🌐Geo: Dprk, Latin american 🔓CVEs: CVE-2023-3519 \[[Vulners](https://vulners.com/cve/CVE-2023-3519)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - citrix netscaler_application_delivery_controller (<12.1-55.297, <13.0-91.13, <13.1-37.159, <13.1-49.13) - citrix netscaler_gateway (<13.0-91.13, <13.1-49.13) CVE-2026-44963 \[[Vulners](https://vulners.com/cve/CVE-2026-44963)] - CVSS V3.1: *9.4*, - Vulners: Exploitation: True CVE-2026-12569 \[[Vulners](https://vulners.com/cve/CVE-2026-12569)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ptc flexplm (le11.0m030, 11.1m020, 11.2.1.0, 12.0.0.0, 12.0.2.0) CVE-2023-34362 \[[Vulners](https://vulners.com/cve/CVE-2023-34362)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - progress moveit_cloud (<14.0.5.45, <14.1.6.97, <15.0.2.39) - progress moveit_transfer (<2021.0.7, <2021.1.5, <2022.0.5, <2022.1.6, <2023.0.2) CVE-2023-27532 \[[Vulners](https://vulners.com/cve/CVE-2023-27532)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - veeam veeam_backup_\&_replication (<11.0.1.1261, 12.0.0.1420) CVE-2024-40711 \[[Vulners](https://vulners.com/cve/CVE-2024-40711)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - veeam veeam_backup_\&_replication (<12.2.0.334) CVE-2023-0669 \[[Vulners](https://vulners.com/cve/CVE-2023-0669)] - CVSS V3.1: *7.2*, - Vulners: Exploitation: True Soft: - fortra goanywhere_managed_file_transfer (<7.1.2) CVE-2025-33073 \[[Vulners](https://vulners.com/cve/CVE-2025-33073)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - microsoft windows_10_1507 (<10.0.10240.21034) - microsoft windows_10_1607 (<10.0.14393.8148) - microsoft windows_10_1809 (<10.0.17763.7434) - microsoft windows_10_21h2 (<10.0.19044.5965) ... 📚TTPs: ⚔️Tactics: 3 🛠️Technics: 0 🤖LLM extracted TTPs:` T1068, T1078, T1210 🧨IOCs: - File: 14 - Hash: 1 💽Software: MSSQL, PostgreSQL, Hyper-V, curl, PDQ Deploy, Windows Defender, FortiGate, PsExec, MOVEit, GoAnywhere, ... 🔢Algorithms: chacha20, md5 ⚙️Win Services: SQLAgent$VEEAMSQL2008R2, VeeamTransportSvc, BackupExecJobEngine, SQLSERVERAGENT, Symantec System Recovery 📜Programming Languages: powershell #threatreport: CVE-2026-44963 is described as a critical remote code execution vulnerability affecting Veeam Backup & Replication 12.x. The flaw reportedly involves insecure deserialization and allows a low-privileged, authenticated domain user to execute arbitrary code over the network against a domain-joined Veeam backup server. Successful exploitation can result in SYSTEM-level control of the server, making the vulnerability particularly significant because backup infrastructure often provides access to sensitive data and recovery operations. The report gives the vulnerability a CVSS score of 9.4 and compares it with earlier Veeam deserialization vulnerabilities, including CVE-2024-40711. The Lynx ransomware group allegedly claimed to use a private or improved version of the vulnerability that does not require domain credentials. An underground forum advertisement similarly claimed to offer an exploit that bypasses the June 2026 patch and achieves unauthenticated SYSTEM-level remote code execution. As of mid-August 2026, these claims had not been independently verified. The report notes that there was no public technical analysis, confirmed exploitation evidence, or vendor acknowledgment demonstrating a genuine unauthenticated bypass or residual vulnerability. The claims may therefore represent negotiation tactics intended to increase ransom demands or protect an alleged exploit. The report also connects the vulnerability to a private exploit advertised in 2025, assessing that it may have been an early version of, or the same underlying issue as, CVE-2026-44963. Veeam has historically been targeted by ransomware groups, including Akira, Fog, Cuba, and FIN7, because compromising backup servers enables attackers to disrupt recovery operations before deploying ransomware. Another major Veeam attack vector is CVE-2023-27532, which can expose credentials from the Veeam backup service and database. Attackers may use these credentials for initial access or lateral movement, including through post-compromise credential-dumping activity. Regardless of whether the alleged unauthenticated exploit exists, the authenticated RCE described for CVE-2026-44963 presents a serious risk wherever domain accounts or backup infrastructure are compromised.

    Post summary

    The report explains the technical details and patch status of VEEAM CVE-2026-44963, noting unverified exploitation claims, and does not confirm active exploitation or provide PoC or exploit code.

    00000241
    779 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    INC ransomware affiliates exploited Citrix NetScaler (CVE-2023-3519) and Fortinet FortiClientEMS (CVE-2023-48788) vulnerabilities before pivoting through RDP sessions with stolen domain admin credentials. Runtime segmentation could limit such lateral movement across compromised networks. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/inc-ransomware-2026

    Post summary

    The post reports that INC ransomware affiliates actively exploited CVE‑2023‑3519 and CVE‑2023‑48788 to pivot via RDP using stolen domain credentials.

    0000069
    1.9K followersView on X
  • ScruteX@scrutexai
    Active Exploitation

    What to patch first, tied to this week's active groups: Fortinet CVE-2024-21762, CVE-2024-55591 (Qilin) SimpleHelp CVE-2024-57727 (DragonForce) VMware ESXi CVE-2024-37085 (Akira) Citrix CVE-2023-3519 (INC Ransom) Full report: https://scrutex.ai/blogs/weekly-ransomware-intelligence-report-june-14-2026 #ransomware #threatintel #CTEM

    Post summary

    The tweet highlights several CVEs being actively exploited by ransomware groups this week, urging organizations to prioritize patching them.

    00000107
    83 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    General

    🔒 #CyberSecurity CVE-2023-3519 &amp; CVE-2023-4966: Critical Citrix NetScaler Exploitation — Detecti… "Defenders are currently facing a critical window of exposure. Recent intelligence from…" 🔗 https://securityarsenal.com/blog/cve-2023-3519-and-cve-2023-4966-critical-citrix-netscaler-exploitation-detection-and-remediation #CyberSecurity #ThreatIntel #vulnerability #cve #patch

    Post summary

    The text announces the existence of CVE‑2023‑3519 and CVE‑2023‑4966 as critical Citrix NetScaler vulnerabilities, but does not provide PoC, exploit code, active exploitation evidence, patches, or detailed technical info.

    0000083
    10 followersView on X
  • Angel Alejos@AlejosAngel
    General

    Descubre cómo se explota CVE-2023-3519 en tiempo real y qué implica para la seguridad. #Ciberseguridad #Exploits https://blog.calif.io/p/a-race-within-a-race-exploiting-cve

    Post summary

    The post mentions a real‑time demonstration of exploiting CVE‑2023‑3519 but lacks technical, patch, or exploit code details.

    0000072
    606 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows INC ransomware group exploited CVE-2023-3519 and spear-phishing to breach healthcare networks across Oceania. Attackers used credential dumping and NETSCAN.EXE for lateral movement before data exfiltration. Runtime segmentation could help contain such post-compromise pivoting. #Ransomware #HealthcareSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/inc-ransomware-group-targets-healthcare-in-oceania-2025

    Post summary

    The TRC analysis reports that the INC ransomware group actively exploited CVE‑2023‑3519 against healthcare networks in Oceania, using credential dumping and lateral movement tools before exfiltration.

    0000064
    1.9K followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    Early 2026 reports show rising cloud compromises via misconfigured services and CVE-2023-3519, CVE-2023-2868, CVE-2021-43798 exploitation, expanding victim impact across sectors. #CloudSecurity https://threatcluster.io/cluster/cloud-compromise-driven-by-security-tool-misuse-and-vulnerab-c2addaf1

    Post summary

    Reports highlight increased cloud compromises driven by exploitation of CVE-2023-3519, CVE-2023-2868, and CVE-2021-43798 across various sectors.

    0000064
    71 followersView on X
  • Proven Data@Proven_Data
    Active Exploitation

    INC ransomware targets Windows, Linux, and ESXi. It exploits Citrix CVE-2023-3519 and Fortinet CVE-2023-48788 to get in. Full attack lifecycle and IOCs → https://www.provendata.com/blog/inc-ransomware/ #Ransomware #CyberSecurity #IncidentResponse #ThreatIntel #InfoSec #DFIR #RansomwareAttack https://t.co/2Ur8piJCz3

    Post summary

    INC ransomware is actively exploiting Citrix CVE-2023-3519 and Fortinet CVE-2023-48788, though the post omits PoC details, exploit code, patches, or technical depth.

    0000096
    913 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_gateway---

Explore more