CVE-2023-4966 — Citrix Netscaler Application Delivery Controller
CISA KEVRansomwareAs of 2025-10-24, CVE-2023-4966 is a CRITICAL-severity vulnerability in Citrix Netscaler Application Delivery Controller, CVSS v3.1 9.4, EPSS 94.3% (99.9th percentile). It is listed in the CISA Known Exploited Vulnerabilities catalog (added 2023-10-18), with a US federal remediation deadline of 2023-11-08, and CISA links it to known ransomware campaigns. Threadlinqs Intelligence links 7 tracked threat campaigns to CVE-2023-4966, most recently “2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)”.
Last updated: 2025-10-24
What is CVE-2023-4966?
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
The record classifies CVE-2023-4966 under weakness classes CWE-119, NVD-CWE-noinfo. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs no prior authentication, needs no user interaction, and has high impact on confidentiality, integrity. 4 affected-product entries are recorded, across 1 vendor, listed below. The identifier was first published 1068 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 9.4 — CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L - EPSS (FIRST)
- 94.3% probability of exploitation in the next 30 days, higher than 99.9% of all scored CVEs
- CISA KEV
- Listed since 2023-10-18, federal remediation deadline 2023-11-08 — used in known ransomware campaigns
- Threadlinqs priority
- 10/10 — CISA lists it as used in ransomware, which Threadlinqs scores at the maximum
- Published
- 2023-10-10, last modified 2025-10-24
Is CVE-2023-4966 being exploited?
CISA added CVE-2023-4966 to the Known Exploited Vulnerabilities catalog on 2023-10-18, which means the agency holds evidence of exploitation in the wild; US federal civilian agencies had to remediate it by 2023-11-08 under BOD 22-01. CISA flags the vulnerability as one used in known ransomware campaigns. It currently carries a trending score of 40 in the Threadlinqs vulnerability feed.
Affected products and versions
- Citrix: Netscaler Application Delivery Controller, Netscaler Gateway
Showing 2 of 4 recorded product entries.
How to fix CVE-2023-4966
The record marks a vendor fix as available for CVE-2023-4966. Patch reference: https://support.citrix.com/article/CTX579459. Vendor advisory: https://support.citrix.com/article/CTX579459. Because CVE-2023-4966 is KEV-listed, US federal civilian agencies were required to apply the vendor fix, or stop using the product, by 2023-11-08. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.
Threat activity tracking CVE-2023-4966
7 tracked threats in the Threadlinqs corpus reference CVE-2023-4966, either in the campaign’s CVE list or as an indicator on the campaign record.
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi) — HIGH · 2026-08-23
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp) — HIGH · 2026-08-21
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands — MEDIUM · 2026-07-22
- CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest Memory Disclosure (CVE-2026-8451) Exploited Within 24 Hours of Disclosure — CRITICAL · 2026-07-02
- CitrixBleed 2.0: CVE-2026-8451 NetScaler SAML IDP Memory Overread Under Active Exploitation — CRITICAL · 2026-06-30
- Kyber Ransomware: Post-Quantum Hybrid Encryption Operation Targeting Windows & VMware ESXi — CRITICAL · 2026-04-22
- INC Ransom Affiliate Network Targeting Pacific Critical Infrastructure (AU/NZ/Tonga Joint Advisory) — CRITICAL · 2026-03-09
Sources
Seeded from nvd and not yet processed by the Threadlinqs enrichment pipeline, so blank CVSS, EPSS or KEV fields above mean NOT MEASURED rather than measured-absent.
← all vulnerabilities · Markdown version · Threadlinqs Intelligence