CVE-2023-3466: Citrix NetScaler Application Delivery Controller

Medium severity, CVSS 6.1. EPSS: 2.6% chance of exploitation in the next 30 days.

Reflected Cross-Site Scripting (XSS)

Affected products

  • Citrix NetScaler Application Delivery Controller: from 12.1, before 12.1-55.297 (fixed in 12.1-55.297); from 13.0, before 13.0-91.13 (fixed in 13.0-91.13); from 13.1, before 13.1-37.159 (fixed in 13.1-37.159); from 13.1, before 13.1-49.13 (fixed in 13.1-49.13); version 11.1-65.22 only
  • Citrix NetScaler Gateway: from 13.0, before 13.0-91.13 (fixed in 13.0-91.13); from 13.1, before 13.1-49.13 (fixed in 13.1-49.13)

Published 2023-07-19. Last modified 2026-06-17.