CVE-2023-3519: Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-07-19. EPSS: 99.7% chance of exploitation in the next 30 days.

Unauthenticated remote code execution

Affected products

  • Citrix NetScaler Application Delivery Controller: from 12.1, before 12.1-55.297 (fixed in 12.1-55.297); from 13.0, before 13.0-91.13 (fixed in 13.0-91.13); from 13.1, before 13.1-37.159 (fixed in 13.1-37.159); from 13.1, before 13.1-49.13 (fixed in 13.1-49.13)
  • Citrix NetScaler Gateway: from 13.0, before 13.0-91.13 (fixed in 13.0-91.13); from 13.1, before 13.1-49.13 (fixed in 13.1-49.13)

Published 2023-07-19. Last modified 2026-08-05.