← Vulnerability feed

Vulnerability record · CVE-2023-4966 · published 10 October 2023

CVE-2023-4966: Citrix NetScaler ADC and Gateway buffer overflow leaks session tokens

Citrix · Netscaler Application Delivery Controller

A memory buffer overflow in NetScaler ADC and NetScaler Gateway, when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, allows sensitive information disclosure. The flaw, tracked as CitrixBleed, leaks session tokens that attackers can reuse to bypass authentication. It matters because the affected appliances are internet-facing remote access points and the vulnerability is confirmed exploited in the wild.

7.5 CVSS 3.1 High CISA KEV since 18 Oct 2023 Known ransomware use EPSS 100% · top 0.1% CWE-119 · Memory buffer overflow
7.5CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
5References
31 Jul 2026Last modified by NVD

Description

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityActively exploited in the wild, listed in CISA KEV with known ransomware use, and near-maximum EPSS probability on internet-facing remote access appliances.

What it is

A memory buffer overflow in NetScaler ADC and NetScaler Gateway, when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, allows sensitive information disclosure. The flaw, tracked as CitrixBleed, leaks session tokens that attackers can reuse to bypass authentication. It matters because the affected appliances are internet-facing remote access points and the vulnerability is confirmed exploited in the wild.

Impact

An unauthenticated attacker can read sensitive memory contents, including session tokens, and use them to hijack authenticated sessions. This can grant access to internal resources and, per CISA, has been linked to ransomware deployment.

Attack surface

Reachable over the network via the affected Gateway or AAA virtual server; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Only appliances configured in those specific roles are exposed.

Exploitation

CISA KEV lists it as actively exploited with known ransomware campaign use, and EPSS probability is 0.99999 (99.998th percentile). Public proof-of-concept code for session token leakage is referenced.

What to do

  • Apply the vendor security update for NetScaler ADC and NetScaler Gateway per Citrix advisory CTX579459.
  • After patching, kill all active and persistent sessions as instructed by Citrix and CISA.
  • If patching is not immediately possible, apply vendor mitigations or discontinue use of the affected Gateway/AAA virtual server configuration.
  • Restrict management and Gateway access to trusted networks where feasible and monitor for anomalous session reuse.

Detection

  • Hunt for unusual session token reuse or authentication from unexpected source IPs against NetScaler Gateway.
  • Review NetScaler logs for memory disclosure indicators or abnormal HTTP responses from the Gateway/AAA virtual server.
  • Monitor for post-exploitation activity consistent with ransomware staging on systems reachable through the appliance.
  • Correlate NetScaler session identifiers with downstream authentication events to spot hijacked sessions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-4966 to the Known Exploited Vulnerabilities catalog on 18 October 2023 as "Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations and kill all active and persistent sessions per vendor instructions [https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/] OR discontinue use of the product if mitigations are unavailable. Federal deadline 8 November 2023.

Ransomware crews whose documented playbooks reference this CVE: