← Vulnerability feed

Vulnerability record · CVE-2023-3519 · published 19 July 2023

CVE-2023-3519: Citrix NetScaler ADC and Gateway unauthenticated code injection

Citrix · Netscaler Application Delivery Controller

Citrix NetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that allows unauthenticated remote code execution. The vendor bulletin covers this CVE alongside CVE-2023-3466 and CVE-2023-3467, and the record does not specify affected versions. Because the flaw is remotely reachable without credentials and has been exploited in the wild, it is a top-tier risk for any internet-facing deployment.

9.8 CVSS 3.1 Critical CISA KEV since 19 Jul 2023 Known ransomware use EPSS 100% · top 0.1% CWE-94 · Code injection
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
5References, 2 tagged exploit
5 Aug 2026Last modified by NVD

Description

Unauthenticated remote code execution

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a 9.8 CVSS score, KEV listing, ransomware use flag and near-certain EPSS probability.

What it is

Citrix NetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that allows unauthenticated remote code execution. The vendor bulletin covers this CVE alongside CVE-2023-3466 and CVE-2023-3467, and the record does not specify affected versions. Because the flaw is remotely reachable without credentials and has been exploited in the wild, it is a top-tier risk for any internet-facing deployment.

Impact

An attacker can execute arbitrary code on the appliance, gaining full control of the device with high confidentiality, integrity and availability impact. Compromise of a NetScaler can expose session traffic and provide a foothold into the internal network.

Attack surface

Reachable over the network via the appliance's web-facing interface, per the CVSS vector AV:N/PR:N/UI:N. No authentication or user interaction is required, so any exposed NetScaler ADC or Gateway instance is a candidate target.

Exploitation

Listed in CISA KEV since 2023-07-19 with a 2023-08-09 remediation due date and flagged for known ransomware campaign use; EPSS 30-day probability is 0.99749 (99.95th percentile). A public exploit reference exists (Packet Storm), confirming active exploitation.

What to do

  • Apply the Citrix security bulletin CTX561482 updates for NetScaler ADC and NetScaler Gateway immediately.
  • If patching cannot be done at once, follow the vendor's mitigation guidance or take the appliance off the internet until it is fixed.
  • Restrict management and user-facing access to trusted networks and IP ranges where operationally possible.
  • Rotate credentials and inspect the appliance for signs of tampering after patching, since code execution may have already occurred.
  • Track the CISA KEV due date (2023-08-09) to confirm remediation is completed on schedule.

Detection

  • Review NetScaler and web server logs for unexpected POST requests or anomalous URI patterns preceding code execution.
  • Monitor for new or modified files, unexpected processes, and outbound connections from the appliance.
  • Alert on authentication or configuration changes made outside normal maintenance windows.
  • Use the vendor bulletin and CISA KEV entry to build asset checks confirming all NetScaler ADC and Gateway instances are on a fixed build.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-3519 to the Known Exploited Vulnerabilities catalog on 19 July 2023 as "Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 9 August 2023.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-3519 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-19490Citrix NetScaler ADC and Gateway authentication bypass via alternate pathNetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel (CWE-288). The flaw is remotely reachable witho…KEVEPSS 7.0%analysed9.3CVE-2026-3055Citrix NetScaler ADC and Gateway SAML IDP memory overreadNetScaler ADC and NetScaler Gateway, when configured as a SAML identity provider, fail to validate input sufficiently, causing an out-of-bounds memor…KEVEPSS 4.0%analysed9.3CVE-2025-5777Citrix NetScaler ADC/Gateway memory overread via insufficient input validationCVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance…KEVEPSS 100%analysed9.2CVE-2025-7775Citrix NetScaler memory overflow allows remote code executionNetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that can lead to remote code execution or denial of service. It affect…KEVEPSS 20%analysed9.2CVE-2025-6543Citrix NetScaler ADC and Gateway memory overflow allows control flow hijack and DoSNetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that causes unintended control flow and denial of service. It affects …KEVEPSS 11%analysed8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2023-6548Citrix NetScaler ADC and Gateway code injection enables low-privileged RCENetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that lets an attacker with access to an NSIP, CLIP or SNIP management inte…KEVEPSS 3.2%analysed7.5CVE-2023-6549Citrix NetScaler ADC and Gateway out-of-bounds memory read and DoSNetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer (CWE-119), allowing an out-of-…KEVEPSS 58%analysed

Source: NIST National Vulnerability Database (record CVE-2023-3519), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.