CVE-2023-4966Disclosure(citrix / netscaler_application_delivery_controller)

MEDIUMCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch citrix netscaler_application_delivery_controller systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

4.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-11-08. Apply mitigations and kill all active and persistent sessions per vendor instructions [https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/] OR discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-119

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netscaler_application_delivery_controller
  • netscaler_gateway

Threat summary

  • Active exploitation appears in 6 classified signals
  • Patch or workaround signal is available
  • 19 mentions across 14 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 6 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 13d ago at 3 mentions (2026-03-02); latest day: 2
  • 19 total mentions across 14 days

Affected systems

Vendors
Products
netscaler_application_delivery_controllernetscaler_gateway

Deep dive

Activity timeline19 mentions / 14d
01223Mentions · 2026-03-02: 3Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-29: 2Mentions · 2026-03-31: 2Mentions · 2026-04-15: 1Mentions · 2026-09-04: 1Mentions · 2026-09-25: 1Mentions · 2026-09-28: 1Mentions · 2026-09-29: 1Mentions · 2026-09-30: 1Mentions · 2026-10-01: 1Mentions · 2026-10-05: 1Mentions · 2026-10-07: 2Active Exploitation · 2026-03-16: 1Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-03-31: 2Active Exploitation · 2026-09-04: 1Active Exploitation · 2026-09-25: 1Patch / Workaround · 2026-03-29: 2Patch / Workaround · 2026-03-31: 2Patch / Workaround · 2026-09-25: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-29: 2Technical Details · 2026-03-31: 1Technical Details · 2026-09-04: 103-0203-1603-1703-2903-3104-1509-0409-2509-2809-2909-3010-0110-0510-07
Signal classification3 categories
Disclosure
541.7%
Active Exploitation
541.7%
Patch
216.7%
Referenced assets15 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-023
Disclosure3
2026-03-161
Active Exploitation1
2026-03-171
Active Exploitation1
2026-03-292
Disclosure1Patch1
2026-03-312
Active Exploitation1Patch1
2026-04-151
Disclosure1
2026-09-041
Active Exploitation1
2026-09-251
Active Exploitation1
Full discourse19 posts
  • Defused@DefusedCyber
    Active Exploitation

    ⚠️ We are observing an active exploitation campaign targeting Citrix NetScaler instances We have observed 500+ exploit attempts of both CitrixBleeds (CVE-2025-5777 and CVE-2023-4966) against our NetScaler decoys across multiple regions: 193.24.211.86 AS215929 🇧🇬 Data Campus Limited 173.164.73.25 AS7922 🇺🇸 Comcast Cable Communications 91.92.243.126 AS202412 🇳🇱 Omegatech LTD 194.31.223.238 AS215439 🇩🇪 PLAY2GO INTERNATIONAL LIMITED Highly elevated exploit activity against older vulnerabilities can often precede a zero-day vulnerability Monitor exploitation of edge devices like Citrix NetScaler in real time 👉 http://console.defusedcyber.com/signup

    Post summary

    The post reports an active exploitation campaign against Citrix NetScaler, with over 500 exploit attempts targeting CVE-2025-5777 and CVE-2023-4966, but offers no patch or PoC details.

    1251672611.0K
    6.2K followersView on X
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    Disclosure

    Citrix Bleed: How a Single Bug Leaked Corporate Secrets (CVE-2023–4966) https://infosecwriteups.com/citrix-bleed-how-a-single-bug-leaked-corporate-secrets-cve-2023-4966-45e9c6fbe9f6?source=rss------bug_bounty-5 #bugbounty #bugbountytips #bugbountytip

    Post summary

    The article announces the discovery of CVE-2023‑4966 in Citrix, noting that a single bug led to corporate data leaks, but it provides no further technical, exploit, or patch details.

    11044765
    40.3K followersView on X
  • TheDarkForge@DarkForgeNews
    Disclosure

    [BREAKING] Attackers probe Citrix NetScaler for CVE-2026-3055 memory overread flaw watchTowr and Defused Cyber reported active reconnaissance on Citrix NetScaler ADC and Gateway for CVE-2026-3055 on March 28, 2026, with CVSS score 9.3. The flaw, an insufficient input validation issue leading to memory overread, affects only systems configured as SAML Identity Providers. Citrix issued security patches on March 23, 2026, but watchTowr Intel reported on March 29 that reconnaissance activity is already visible across honeypot networks. Unauthenticated attackers can leak sensitive data from appliance memory. Organizations can identify vulnerable configurations by searching for the string "add authentication samlIdPProfile" in Citrix administrative settings. Citrix discovered the flaw internally; no public proof-of-concept code exists. CVE-2023-4966 (CitrixBleed), a similar memory-leak vulnerability, was widely exploited in 2023 after disclosure. Citrix vulnerabilities have shown rapid progression from reconnaissance to exploitation. Organizations running affected NetScaler versions—14.1 before 14.1-66.59, 13.1 before 13.1-62.23, and 13.1-FIPS/13.1-NDcPP before 13.1-37.262—should apply patches immediately. — THE FORGE'S WEIGHT — Active reconnaissance signals imminent exploitation risk for SAML IDP configurations on NetScaler. watchTowr Intel detects probes testing authentication flows; once exploitation begins, response windows shrink to hours. Many critical infrastructure teams lack visibility into their SAML IDP status.

    Post summary

    The post announces that attackers are probing for the newly disclosed CVE‑2026‑3055, an unchecked memory‑overread flaw in Citrix NetScaler’s SAML IDP modules, with no PoC or exploit yet, but patches are available and active reconnaissance is observed.

    00010122
    20 followersView on X
  • VulnTracker@vuln_tracker
    Active Exploitation

    @DefusedCyber Active CitrixBleed exploitation across multiple regions is concerning! CVE-2025-5777 and CVE-2023-4966 getting hammered means any unpatched NetScaler is getting hit. Track it now: http://vulntracker.io

    Post summary

    The tweet reports active exploitation of CVE-2025-5777 and CVE-2023-4966 across regions, but offers no specific technical details, PoC, or patch information.

    00001721
    429 followersView on X
  • Marcelo Pontes 🇧🇷🏄‍♂️🇻🇪@PontesVPBR

    @TSEjusbr https://www.cisa.gov/news-events/analysis-reports/ar21-112a e https://www.cisa.gov/guidance-addressing-citrix-netscaler-adc-and-gateway-vulnerability-cve-2023-4966-citrix-bleed

    0000074
    3.5K followersView on X
  • Bhavesh Verma@xbhaveshverma

    CVEs explainer #7 CVE-2023-4966 (Citrix Bleed) A critical information disclosure vulnerability in Citrix NetScaler ADC and Gateway. By sending specially crafted requests, attackers could leak session tokens from device memory. This allowed them to hijack legitimate user sessions, bypassing passwords and multi-factor authentication entirely. It was widely exploited by LockBit ransomware affiliates.

    0000099
    103 followersView on X
  • nksistemas@nksistemas

    Alerta Roja: Explotación Activa de Vulnerabilidades Críticas en Citrix NetScaler (CVE-2023-4966 y CVE-2023-4967) https://nksistemas.com/alerta-roja-explotacion-activa-de-vulnerabilidades-criticas-en-citrix-netscaler-cve-2023-4966-y-cve-2023-4967/

    00000150
    6.2K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis shows attackers exploiting CVE-2023-4966 in Citrix NetScaler devices are deploying PHP web shells disguised as CSS resources to maintain persistence. The campaign creates superuser accounts and exfiltrates configuration data while evading detection through legitimate-looking URLs. Runtime segmentation helps contain post-compromise lateral movement across network infrastructure. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/citrix-netscaler-cve-2026-88771-post-exploitation-web-shell-css-urls

    0000073
    2.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis shows attackers exploiting CVE-2023-4966 through crafted DTLS handshake records to achieve pre-authentication RCE on Citrix NetScaler infrastructure. Compromise of network perimeter devices enables lateral movement into internal segments. #ZeroDay #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/citrix-netscaler-cve-2026-88772-exploit

    0000072
    2.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis reveals attackers exploited critical NetScaler zero-days CVE-2023-4966 and CVE-2023-4967 for remote code execution, then pivoted through compromised appliances to access internal network segments. Runtime segmentation helps contain post-compromise lateral movement. #ZeroDay #ZeroTrust 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/citrix-netscaler-zero-days-cve-2026-88771-cve-2026-88772-delayed-disclosure

    0000043
    2.0K followersView on X
  • nksistemas@nksistemas

    CVE-2023-4966: Análisis de «Citrix Bleed» y Estrategias de Mitigación para SREs https://nksistemas.com/cve-2023-4966-analisis-de-citrix-bleed-y-estrategias-de-mitigacion-para-sres/

    00000136
    6.2K followersView on X
  • ro0TCr4k@ro0TCr4k
    Active Exploitation

    Citrix Bleed (CVE-2023-4966) is actively exploited. If you're running NetScaler, patch yesterday. Attackers are hijacking sessions faster than your SOC can blink. RootCrak is deep in the detection logs—this one’s nasty.

    Post summary

    The text reports that Citrix Bleed (CVE-2023-4966) is being actively exploited, urges NetScaler users to apply a patch, and mentions detection of RootCrak in logs.

    00000813
    508 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploited CVE-2023-4966 authentication bypass in Citrix NetScaler appliances, gaining administrative access to edge infrastructure. From this trusted network position, threat actors can pivot internally and establish persistent C2 channels that bypass traditional egress controls. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/critical-citrix-netscaler-auth-bypass-cve-2026-19490-attacks

    Post summary

    Attackers have exploited CVE-2023-4966 to bypass authentication on Citrix NetScaler appliances, gaining administrative access and enabling lateral movement within the infrastructure, demonstrating active exploitation in the wild.

    0000085
    2.0K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Disclosure

    🔒 #CyberSecurity CVE-2023-3519 & CVE-2023-4966: Critical Citrix NetScaler Exploitation — Detecti… "Defenders are currently facing a critical window of exposure. Recent intelligence from…" 🔗 https://securityarsenal.com/blog/cve-2023-3519-and-cve-2023-4966-critical-citrix-netscaler-exploitation-detection-and-remediation #CyberSecurity #ThreatIntel #vulnerability #cve #patch

    Post summary

    The tweet alerts that CVE-2023-3519 and CVE-2023-4966 pose a critical risk to Citrix NetScaler, pointing to a blog providing detection and remediation guidance.

    0000083
    10 followersView on X
  • TheDarkForge@DarkForgeNews
    Patch

    [CYBERSEC] CISA mandates federal patch for exploited Citrix NetScaler CVE-2026-3055 by April 2 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on March 30 mandated federal agencies to patch approximately 30,000 exposed Citrix NetScaler ADC appliances for CVE-2026-3055 by April 2. A critical vulnerability in Citrix NetScaler ADC and Gateway devices (CVSS 9.3) is under active exploitation, allowing unauthenticated remote attackers to leak sensitive information from appliances configured as SAML identity providers. Citrix issued patches on March 23. The Canadian Cyber Centre confirmed on March 30 exploitation in the wild since March 27. CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog on March 30 and issued a Binding Operational Directive requiring federal agencies to secure vulnerable devices within three days. Security firm Shadowserver tracks approximately 30,000 NetScaler ADC appliances and over 2,300 Gateway instances exposed online. The vulnerability stems from insufficient input validation leading to a memory overread, allowing attackers to extract sensitive data including administrative session IDs that could enable full device takeover. The flaw requires the target device to be configured as a SAML Identity Provider, a configuration likely common among organizations deploying single sign-on infrastructure. Researchers at Rapid7 note the vulnerability bears a technical resemblance to the widely exploited "CitrixBleed" (CVE-2023-4966) and "CitrixBleed2" flaws. CISA warned that this type of vulnerability poses significant risks to the federal enterprise and recommended all organizations prioritize patching. Cybersecurity firm Watchtowr flagged that attackers could use the vulnerability to steal administrator authentication tokens and potentially assume control of unpatched appliances. Citrix released detailed guidance for customers to identify vulnerable configurations; no public proof-of-concept exploit exists. What remains unclear: the total number of affected devices already patched since March 23, whether any successful data exfiltration has occurred beyond reconnaissance, and the identity of threat actors conducting active exploitation. — THE FORGE'S WEIGHT — The April 2 deadline compresses a patch window into three days for federal agencies. The vulnerability enables session hijacking that renders device credentials worthless, converting network trust into liability. The question is whether the deadline buys time or merely guarantees chaos.

    Post summary

    CISA mandates federal agencies patch Citrix NetScaler CVE‑2026‑3055 by April 2 after the CVSS‑9.3 vulnerability—an actively exploited memory overread in SAML Identity Provider configurations that can leak session IDs and potentially allow full device takeover. A specific patch has already been released by Citrix.

    0000052
    20 followersView on X
  • z3n@zench4n
    Active Exploitation

    Forget goldfish. Hackers have a better memory, and they are using it to bleed your Citrix NetScaler dry. 🐟 CVE-2023-4966 is the unauthorized backstage pass nobody asked for. Patch now or your session tokens become public property. Don't let your data take an unguided tour! 🛡️ https://www.bleepingcomputer.com/news/security/critical-citrix-netscaler-memory-flaw-actively-exploited-in-attacks/ #CyberSecurity #InfoSec #Citrix #PatchTuesday

    Post summary

    CVE-2023-4966 is an actively exploited memory flaw in Citrix NetScaler; an urgent patch is required to prevent session token leakage.

    0000012
    1.4K followersView on X
  • TheDarkForge@DarkForgeNews
    Patch

    [CYBERSEC] Threat actors probe Citrix NetScaler instances after CVE-2026-3055 disclosure watchTowr observed threat actors probing internet-facing Citrix NetScaler devices via its Attacker Eye honeypot network on March 29, 2026. The activity targets NetScaler ADC and NetScaler Gateway instances vulnerable to CVE-2026-3055, an out-of-bounds read flaw (CVSS 9.3) that Citrix disclosed on March 23, 2026, allowing unauthenticated memory reads when configured as SAML IDP. Citrix released patches for CVE-2026-3055 and CVE-2026-4368 in NetScaler versions 14.1 before 14.1-66.59, 13.1 before 13.1-62.23, and others. No sources confirm in-the-wild exploitation or session token extraction as of March 29, 2026. watchTowr indicates actors have begun targeting the flaw post-disclosure. Prior NetScaler flaws like CVE-2023-4966 saw rapid weaponization. Default configurations remain unaffected; SAML IDP setups require checking for "add authentication samlIdPProfile". Mandiant M-Trends 2026 reports do not appear in available sources. Organizations face risk from incomplete patching given historical patterns. Unclear elements include specific threat actors, targeted geography, and successful exploits beyond probing. — THE FORGE'S WEIGHT — Citrix published patches on March 23, 2026, but watchTowr honeypots show actors probing by March 29. No confirmed exploitation exists. Many organizations lack perimeter inventory to identify vulnerable NetScaler instances.

    Post summary

    Citrix issued patches for CVE‑2026‑3055 and CVE‑2026‑4368, while threat actors have started probing affected NetScaler devices, yet no in‑the‑wild exploitation has been confirmed.

    0000085
    20 followersView on X
  • ‘BugBounty Writeups’@bbwriteups
    Disclosure

    "Citrix Bleed: How a Single Bug Leaked Corporate Secrets (CVE-2023–4966)" by Krishna Kumar #BugBounty #Cybersecurity #Hacking #InfoSec https://infosecwriteups.com/citrix-bleed-how-a-single-bug-leaked-corporate-secrets-cve-2023-4966-45e9c6fbe9f6

    Post summary

    The snippet announces a new vulnerability (CVE-2023‑4966) that reportedly leaked corporate secrets, but it provides no technical details, PoC, or evidence of active exploitation.

    0000091
    490 followersView on X
  • ‘BugBounty Writeups’@bbwriteups
    Disclosure

    "Citrix Bleed: How a Single Bug Leaked Corporate Secrets (CVE-2023–4966)" by Krishna Kumar #BugBounty #Cybersecurity #Hacking #InfoSec https://xalgord.medium.com/citrix-bleed-how-a-single-bug-leaked-corporate-secrets-cve-2023-4966-45e9c6fbe9f6

    Post summary

    The article announces the discovery of CVE‑2023‑4966, a Citrix vulnerability that leaked corporate secrets, but it does not provide technical or exploit details.

    0000084
    490 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_gateway---

Explore more