CVE-2023-4966

ENISA EUVD: EUVD-2023-54802 ↗
Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 13 articles Published: 2023-10-10

EPSS Score

Source: FIRST.org · 2026-05-23
94.33%
probability
This CVE has a 94.33% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
9.4
CRITICAL
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Description

VulnerabilityLookup (CNA)
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

Affected Products

Citrix
NetScaler ADC
14.1 13.1 13.0 13.1-FIPS 12.1-FIPS 12.1-NDcPP
Citrix
NetScaler Gateway
14.1 13.1 13.0

Attack Intelligence

Exploits & PoC

Chocapikk/CVE-2023-4966

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy)

79 2023-10-26
dinosn/citrix_cve-2023-4966

Citrix CVE-2023-4966 from assetnote modified for parallel and file handling

11 2023-10-25
RevoltSecurities/CVE-2023-4966

An Exploitation script developed to exploit the CVE-2023-4966 bleed citrix information disclosure vulnerability

10 2023-10-29
mlynchcogent/CVE-2023-4966-POC

Proof Of Concept for te NetScaler Vuln

8 2023-10-25
certat/citrix-logchecker

Parse citrix netscaler logs to check for signs of CVE-2023-4966 exploitation

5 2023-11-03
morganwdavis/overread

Simulates CVE-2023-4966 Citrix Bleed overread bug

2 2023-12-31
0xKayala/CVE-2023-4966

CVE-2023-4966 - NetScaler ADC and NetScaler Gateway Memory Leak Exploit

0 2023-10-28
s-bt/CVE-2023-4966

Scripts to get infos

0 2023-11-20
byte4RR4Y/CVE-2023-4966

Programm to exploit a range of ip adresses

0 2023-11-27
jmussmann/cve-2023-4966-iocs

Python script to search Citrix NetScaler logs for possible CVE-2023-4966 exploitation.

0 2023-12-09
akshthejo/CVE-2023-4966-exploit

CVE-2023-4966-exploit

0 2025-01-17
vignesh-hp/LockBit-Ransomware-Analysis

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

0 2026-02-25
14 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
85%
EPSS 94.33%
CVSS v3.1 9.4
Mentions 13
Last Seen Mar 24, 2026

CNA Information

CNA Assigner
Citrix
CNA Title
Unauthenticated sensitive information disclosure

Analyst Note

CVE-2023-4966 was explicitly named by Citrix as a zero-day exploited in active attacks in October 2023, coinciding with the CVE publication date. The BleepingComputer article directly states 'Citrix warns of new Netscaler zero-days exploited in attacks,' confirming in-the-wild exploitation at or before patch availability.

Threat Actors 38

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Turla Group
apt_group Information theft and espionage Russian Federation
Cobalt
apt_group Financial crime 🇷🇺 RU
MALLARD SPIDER
apt_group Financial gain 🇷🇺 RU
APT37
apt_group Information theft and espionage 🇰🇵 KP
FIN7
apt_group Financial crime 🇷🇺 RU
Cron
apt_group 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
BelialDemon
apt_group 🇷🇺 RU
SCATTERED SPIDER
apt_group Financial crime 🇺🇸 US
FusionCore
apt_group 🇪🇺 EU
The Shadow Brokers
apt_group 🇷🇺 RU
UAC-0020
apt_group 🇺🇦 UA
HAZY TIGER
apt_group Information theft and espionage 🇮🇳 IN
ELECTRUM
apt_group Information theft and espionage 🇷🇺 RU
Infy
apt_group Information theft and espionage 🇮🇷 IR
Andariel Group
apt_group 🇰🇷 KR
Camaro Dragon
apt_group Information theft and espionage 🇨🇳 CN
TA428
apt_group Information theft and espionage 🇨🇳 CN
SideWinder
apt_group 🇮🇳 IN
RAZOR TIGER
apt_group Information theft and espionage 🇮🇳 IN
Larva-208
apt_group 🇷🇺 RU
ShadowSyndicate
apt_group 🇷🇺 RU
UTA0178
apt_group Information theft and espionage 🇨🇳 CN
APT 22
apt_group Information theft and espionage 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Water Bakunawa
apt_group 🇷🇺 RU
Storm-0249
apt_group 🇷🇺 RU
Pat Bear
apt_group 🇸🇾 SY
Operation Red Signature
apt_group Information theft and espionage 🇨🇳 CN
Poseidon Group
apt_group Information theft and espionage 🇧🇷 BR
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
UNC5337
apt_group 🇨🇳 CN
APT 5
apt_group Information theft and espionage 🇨🇳 CN
Beijing Group
apt_group Information theft and espionage 🇨🇳 CN
Operation Black Atlas
apt_group Financial crime

Triage Info

Decided atMar 05, 2026
Published DateOct 10, 2023