CVE-2023-4966

Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 14 articles

EPSS Score

Source: FIRST.org · 2026-05-24
94.35%
probability
This CVE has a 94.35% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Attack Intelligence

Exploits & PoC

Chocapikk/CVE-2023-4966

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy)

80
dinosn/citrix_cve-2023-4966

Citrix CVE-2023-4966 from assetnote modified for parallel and file handling

11
RevoltSecurities/CVE-2023-4966

An Exploitation script developed to exploit the CVE-2023-4966 bleed citrix information disclosure vulnerability

10
mlynchcogent/CVE-2023-4966-POC

Proof Of Concept for te NetScaler Vuln

8
certat/citrix-logchecker

Parse citrix netscaler logs to check for signs of CVE-2023-4966 exploitation

5
morganwdavis/overread

Simulates CVE-2023-4966 Citrix Bleed overread bug

2
IceBreakerCode/CVE-2023-4966

PoC CVE-2023-4966 — IceBreakerCode/CVE-2023-4966

1
0xKayala/CVE-2023-4966

CVE-2023-4966 - NetScaler ADC and NetScaler Gateway Memory Leak Exploit

0
s-bt/CVE-2023-4966

Scripts to get infos

0
byte4RR4Y/CVE-2023-4966

Programm to exploit a range of ip adresses

0
10 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
85%
EPSS 94.35%
Mentions 14
Last Seen May 27, 2026

CNA Information

Analyst Note

CVE-2023-4966 was explicitly named by Citrix as a zero-day exploited in active attacks in October 2023, coinciding with the CVE publication date. The BleepingComputer article directly states 'Citrix warns of new Netscaler zero-days exploited in attacks,' confirming in-the-wild exploitation at or before patch availability.

Threat Actors 38

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Turla Group
apt_group Information theft and espionage Russian Federation
Cobalt
apt_group Financial crime 🇷🇺 RU
MALLARD SPIDER
apt_group Financial gain 🇷🇺 RU
APT37
apt_group Information theft and espionage 🇰🇵 KP
FIN7
apt_group Financial crime 🇷🇺 RU
Cron
apt_group 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
BelialDemon
apt_group 🇷🇺 RU
SCATTERED SPIDER
apt_group Financial crime 🇺🇸 US
FusionCore
apt_group 🇪🇺 EU
The Shadow Brokers
apt_group 🇷🇺 RU
UAC-0020
apt_group 🇺🇦 UA
HAZY TIGER
apt_group Information theft and espionage 🇮🇳 IN
ELECTRUM
apt_group Information theft and espionage 🇷🇺 RU
Infy
apt_group Information theft and espionage 🇮🇷 IR
Andariel Group
apt_group 🇰🇷 KR
Camaro Dragon
apt_group Information theft and espionage 🇨🇳 CN
TA428
apt_group Information theft and espionage 🇨🇳 CN
SideWinder
apt_group 🇮🇳 IN
RAZOR TIGER
apt_group Information theft and espionage 🇮🇳 IN
Larva-208
apt_group 🇷🇺 RU
ShadowSyndicate
apt_group 🇷🇺 RU
UTA0178
apt_group Information theft and espionage 🇨🇳 CN
APT 22
apt_group Information theft and espionage 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Water Bakunawa
apt_group 🇷🇺 RU
Storm-0249
apt_group 🇷🇺 RU
Pat Bear
apt_group 🇸🇾 SY
Operation Red Signature
apt_group Information theft and espionage 🇨🇳 CN
Poseidon Group
apt_group Information theft and espionage 🇧🇷 BR
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
UNC5337
apt_group 🇨🇳 CN
APT 5
apt_group Information theft and espionage 🇨🇳 CN
Beijing Group
apt_group Information theft and espionage 🇨🇳 CN
Operation Black Atlas
apt_group Financial crime

Triage Info

Decided atMar 05, 2026