Active Exploitation Alert: Citrix NetScaler ADC & Gateway Vulnerability (CVE-2023-4966) CitrixBleed-ing Again Under Massive Attack

Active Exploitation Alert: Citrix NetScaler ADC & Gateway Vulnerability (CVE-2023-4966) CitrixBleed-ing Again Under Massive Attack

By Rescana
Publication Date: 2026-07-07 00:00:00

Executive Summary

A new critical vulnerability, widely referred to as CitrixBleed-ing Again, has been identified in Citrix NetScaler ADC and NetScaler Gateway appliances. This flaw, tracked as CVE-2023-4966, enables remote, unauthenticated attackers to extract sensitive memory contents, including session tokens and credentials, from affected devices. The vulnerability is being actively exploited in the wild, with public proof-of-concept code and detection scripts accelerating the risk of mass exploitation. The flaw is rooted in improper memory handling during the parsing of authentication requests, particularly when the appliance is configured as a SAML Identity Provider (IdP) or as a Gateway. Organizations using vulnerable versions of NetScaler ADC or Gateway are at immediate risk of compromise and must take urgent action to patch, monitor, and mitigate exposure.

Threat Actor Profile

Current intelligence indicates that exploitation of CVE-2023-4966 is opportunistic and…