CVE-2023-4966: Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2023-10-18. EPSS: 100% chance of exploitation in the next 30 days.

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

Affected products

  • Citrix NetScaler Application Delivery Controller: from 12.1, before 12.1-55.300 (fixed in 12.1-55.300); from 13.0, before 13.0-92.19 (fixed in 13.0-92.19); from 13.1, before 13.1-37.164 (fixed in 13.1-37.164); from 13.1, before 13.1-49.15 (fixed in 13.1-49.15); from 14.1, before 14.1-8.50 (fixed in 14.1-8.50)
  • Citrix NetScaler Gateway: from 13.0, before 13.0-92.19 (fixed in 13.0-92.19); from 13.1, before 13.1-49.15 (fixed in 13.1-49.15); from 14.1, before 14.1-8.50 (fixed in 14.1-8.50)

Published 2023-10-10. Last modified 2026-07-31.