CVE-2022-27518
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
5 articles
EPSS Score
Source: FIRST.org · 2026-05-24
27.69%
probability
This CVE has a 27.69% probability
of being exploited in the next 30 days.
0%
Top 96.5th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroImproper access restrictions in SAML SP & IdP systems
Google Project Zero
Patched
Dec. 13, 2022
Reported by
???
Root Cause Analysis
???
Hackers exploit critical Citrix ADC and Gateway zero day, patch now
BleepingComputer
Dec 13, 2022
Qualys Threat Research Unit: Threat Thursdays, December 2022
Qualys
Dec 29, 2022
Security Advisory 2022-087
CERT-EU
Dec 13, 2022
Signal Intelligence
Confidence
92%
EPSS
27.69%
Mentions
5
Last Seen
Dec 29, 2022
CNA Information
Analyst Note
CVE-2022-27518 is a critical unauthenticated RCE vulnerability (CVSS 9.8) affecting widely-deployed Citrix products, with official vendor security advisory from CERT-EU confirming the threat. The presence in Google Project Zero and multiple security organization documentation provides strong corroboration of the vulnerability's legitimacy and severity.
Threat Actors 1
Pitty Panda
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 03, 2026