Critical severity9.4CISA KEVNVD Advisory· Published Oct 10, 2023· Updated Jul 31, 2026
CVE-2023-4966
CVE-2023-4966
Description
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*+ 2 more
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*range: >=13.0,<13.0-92.19
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*range: >=12.1,<12.1-55.300
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*range: >=12.1,<12.1-55.300
cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*range: >=13.0,<13.0-92.19
- (no CPE)range: 14.1
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 14.1
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/175323/Citrix-Bleed-Session-Token-Leakage-Proof-Of-Concept.htmlnvdThird Party AdvisoryVDB Entry
- support.citrix.com/article/CTX579459nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
6- Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate NetworksCyber Security News · Jul 27, 2026
- CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public DisclosureCyber Security News · Jul 2, 2026
- INC Ransomware Uses Rust-Based Windows and Linux/ESXi Encryptors in New AttacksCyber Security News · Jun 19, 2026
- The Gentlemen Ransomware Group Uses Fortinet Exploits, AI, and Custom C2 FrameworksCyber Security News · Jun 3, 2026
- Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersectTenable Blog · May 27, 2026
- Ransomware Tactics, Techniques, and Procedures in a Shifting Threat LandscapeMandiant Threat Intelligence · Mar 16, 2026