CVE-2023-4966

CRITICAL KEV RANSOMWARE NUCLEI

Citrix NetScaler ADC/Gateway 12.1-55.300/13.0-92.19 Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-4966 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added October 18, 2023, with confirmed use in ransomware campaigns. EIP tracks 19 public exploits from researchers including Chocapikk, dinosn, RevoltSecurities, including a Metasploit module auxiliary/scanner/http/citrix_netscaler_cve_2026_3055. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2023-4966, a memory leak vulnerability in Citrix ADC instances. The exploit sends a crafted HTTP request with a long 'Host' header to trigger a memory dump, then extracts and validates session tokens from the response.

Description

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

Exploits (19)

nomisec WORKING POC 80 stars
by Chocapikk · infoleak
https://github.com/Chocapikk/CVE-2023-4966

This repository contains a functional Python exploit for CVE-2023-4966, a memory leak vulnerability in Citrix ADC instances. The exploit sends a crafted HTTP request with a long 'Host' header to trigger a memory dump, then extracts and validates session tokens from the response.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Citrix ADC / Gateway (affected versions not specified)
No auth needed
Prerequisites: Network access to the target Citrix ADC instance · Python 3.10 with required dependencies (requests, rich, alive_progress, hexdump)
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 11 stars
by dinosn · infoleak
https://github.com/dinosn/citrix_cve-2023-4966

This repository contains a functional Python script that exploits CVE-2023-4966 (Citrix Bleed) to leak session tokens by sending a crafted HTTP request with an oversized Host header. The script supports both single-target and multi-target scanning via a file input.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Citrix ADC / Gateway
No auth needed
Prerequisites: Network access to the target Citrix ADC/Gateway
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 10 stars
by RevoltSecurities · infoleak
https://github.com/RevoltSecurities/CVE-2023-4966

This repository contains a functional exploit script for CVE-2023-4966, a Citrix Bleed information disclosure vulnerability. The script sends a crafted HTTP request with a long 'Host' header to dump memory contents from vulnerable Citrix Gateway instances.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Citrix Gateway (unspecified version)
No auth needed
Prerequisites: Network access to vulnerable Citrix Gateway instance
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 8 stars
by mlynchcogent · infoleak
https://github.com/mlynchcogent/CVE-2023-4966-POC

This repository contains a functional Python exploit for CVE-2023-4966, a critical vulnerability in Citrix ADC/NetScaler Gateways that allows unauthenticated attackers to leak session tokens via memory dumping. The exploit sends a crafted HTTP request with an oversized 'Host' header to trigger the vulnerability and extracts valid session tokens from the response.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Citrix ADC/NetScaler Gateway (configured as Gateway or AAA virtual server)
No auth needed
Prerequisites: Network access to the target Citrix ADC/NetScaler instance · Target must be configured as a Gateway or AAA virtual server
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec SCANNER 5 stars
by certat · poc
https://github.com/certat/citrix-logchecker

This repository contains a Perl script designed to parse Citrix NetScaler logs for signs of CVE-2023-4966 exploitation by detecting anomalous session reconnects. It does not exploit the vulnerability but scans logs for indicators of compromise.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Citrix NetScaler (affected by CVE-2023-4966)
No auth needed
Prerequisites: Access to Citrix NetScaler syslog files
devstral-2 · analyzed Feb 18, 2026 Full analysis →
github WORKING POC 2 stars
by Pr0t0c01 · pythonpoc
https://github.com/Pr0t0c01/CVEs/tree/main/Citrix_CVE-2023-4966

The repository contains functional exploit code for CVE-2023-4966, targeting Citrix Gateway. The exploit is written in Python and demonstrates an information disclosure vulnerability. The repository also includes YAML templates for Nuclei scanning and README files with technical details for multiple CVEs.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Citrix Gateway
No auth needed
Prerequisites: Target list in domain or IP:port format
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC 2 stars
by morganwdavis · infoleak
https://github.com/morganwdavis/overread

This repository contains a functional C program demonstrating the buffer overread vulnerability (CVE-2023-4966) in Citrix systems. It simulates how `snprintf` truncation can lead to memory overreads, exposing sensitive data.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Citrix NetScaler ADC and Gateway (CVE-2023-4966)
No auth needed
Prerequisites: Basic understanding of buffer overreads · C compiler to run the demonstration
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 1 stars
by IceBreakerCode · infoleak
https://github.com/IceBreakerCode/CVE-2023-4966

This repository contains a functional Python script that exploits CVE-2023-4966, a vulnerability in Citrix Gateway or ADC. The exploit sends a crafted HTTP request with an oversized 'Host' header to trigger an information leak via the '/oauth/idp/.well-known/openid-configuration' endpoint.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Citrix Gateway or ADC
No auth needed
Prerequisites: Network access to the target Citrix Gateway or ADC
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WRITEUP
by vignesh-hp · poc
https://github.com/vignesh-hp/LockBit-Ransomware-Analysis

This repository provides a detailed threat intelligence analysis of the LockBit ransomware attack exploiting CVE-2023-4966 (Citrix Bleed). It covers the attack lifecycle, MITRE ATT&CK mapping, and defensive recommendations but does not include functional exploit code.

Classification
Writeup 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Theoretical
Target: Citrix NetScaler
No auth needed
Prerequisites: access to vulnerable Citrix NetScaler instance
devstral-2 · analyzed Feb 25, 2026 Full analysis →
nomisec STUB
by akshthejo · poc
https://github.com/akshthejo/CVE-2023-4966-exploit

The repository contains an empty exploit.py file with no functional code or technical details. No exploit logic, payload, or vulnerability analysis is present.

Classification
Stub 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by LucasOneZ · infoleak
https://github.com/LucasOneZ/CVE-2023-4966

This repository contains a functional exploit for CVE-2023-4966, targeting Citrix ADC/Gateway. The exploit includes methods to check for vulnerability, curl a URL with formatted XML response, and dump memory by manipulating the Host header to trigger a buffer overflow.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Citrix ADC/Gateway
No auth needed
Prerequisites: Network access to the target Citrix ADC/Gateway · Target endpoint must be accessible
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec SCANNER
by jmussmann · poc
https://github.com/jmussmann/cve-2023-4966-iocs

This repository contains a Python script that scans Citrix NetScaler logs for indicators of compromise (IoCs) related to CVE-2023-4966 exploitation. It does not exploit the vulnerability but detects potential exploitation attempts by analyzing log patterns.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Citrix NetScaler
No auth needed
Prerequisites: Access to Citrix NetScaler log files
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec SCANNER
by byte4RR4Y · infoleak
https://github.com/byte4RR4Y/CVE-2023-4966

The repository contains a Go-based tool that scans a range of IP addresses for Citrix Bleed (CVE-2023-4966) by checking for vulnerable endpoints and extracting sensitive information from responses. It does not include exploit code for achieving remote code execution but detects potential vulnerabilities.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Citrix NetScaler ADC and Gateway
No auth needed
Prerequisites: Network access to target IP range · Vulnerable Citrix endpoint exposed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec SCANNER
by s-bt · poc
https://github.com/s-bt/CVE-2023-4966

The repository contains PowerShell scripts designed to detect potential exploitation of CVE-2023-4966 by analyzing Citrix VDA registry entries and NetScaler logs for suspicious activity, such as mismatched client IP addresses. It does not include exploit code but provides forensic tools for post-compromise analysis.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Citrix NetScaler ADC and Gateway, Citrix Virtual Delivery Agent (VDA)
Auth required
Prerequisites: Access to Active Directory for querying Citrix servers · PowerShell Remoting enabled on target VDAs · NetScaler log files (ns.log) for analysis
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by 0xKayala · infoleak
https://github.com/0xKayala/CVE-2023-4966

This repository contains a functional Python script that exploits CVE-2023-4966, a memory leak vulnerability in NetScaler ADC and Gateway. The script sends a crafted HTTP request to trigger sensitive information disclosure, including session tokens.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: NetScaler ADC and NetScaler Gateway
No auth needed
Prerequisites: Network access to the target NetScaler ADC/Gateway
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit SCANNER
by watchTowr, sfewer-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/citrix_netscaler_cve_2026_3055.rb

This Metasploit module scans for CVE-2026-3055, a memory leak vulnerability in Citrix ADC (NetScaler) configured as a SAML IdP. It sends crafted HTTP requests to trigger the vulnerability and checks for leaked session cookies in the response.

Classification
Scanner 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Citrix ADC (NetScaler) configured as a SAML IdP
No auth needed
Prerequisites: Target must be a Citrix ADC (NetScaler) configured as a SAML IdP
devstral-2 · analyzed May 20, 2026 Full analysis →
vulncheck_xdb WORKING POC
infoleak
https://github.com/spmonkey/GHR

This repository contains a functional exploit PoC for CVE-2023-4966, targeting Citrix NetScaler ADC and Gateway. The code includes a modular framework for vulnerability scanning, directory mapping, and exploitation, with specific modules for CVE-2023-4966 and other vulnerabilities.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Citrix NetScaler ADC and Gateway
No auth needed
Prerequisites: network access to target · Python environment with required dependencies
devstral-2 · analyzed Feb 25, 2026 Full analysis →
vulncheck_xdb WORKING POC
remote
https://github.com/assetnote/exploits

The repository contains functional exploit code for CVE-2023-4966, targeting Citrix NetScaler. The exploit leverages a deserialization vulnerability to achieve remote code execution (RCE). The provided Python script constructs a malicious payload and sends it to the target system to execute arbitrary commands.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Citrix NetScaler
No auth needed
Prerequisites: Network access to the target system · Python environment with required libraries
devstral-2 · analyzed Feb 25, 2026 Full analysis →
metasploit SCANNER
by Dylan Pindur, Spencer McIntyre · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/citrix_bleed_cve_2023_4966.rb

This Metasploit module scans for CVE-2023-4966 (Citrix Bleed), a vulnerability in Citrix ADC (NetScaler) that allows unauthenticated memory leakage. It checks for leaked session cookies and attempts to validate them by querying the target for associated usernames.

Classification
Scanner 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Citrix ADC (NetScaler)
No auth needed
Prerequisites: Network access to the target Citrix ADC server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Citrix Bleed - Leaking Session Tokens
HIGHVERIFIEDby DhiyaneshDK
Shodan: title:"Citrix Gateway" || title:"Netscaler Gateway" || http.title:"citrix gateway" || title:"netscaler gateway"
FOFA: title="citrix gateway" || title:"netscaler gateway"

Scores

CVSS v3 9.4
EPSS 0.9435
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2023-10-18
VulnCheck KEV 2023-10-17
InTheWild.io 2023-10-18
ENISA EUVD EUVD-2023-54802
Ransomware Use Confirmed
CWE
CWE-119
Status published
Products (3)
citrix/netscaler_application_delivery_controller 12.1 - 12.1-55.300 (2 CPE variants)
citrix/netscaler_application_delivery_controller 13.0 - 13.0-92.19
citrix/netscaler_gateway 13.0 - 13.0-92.19
Published Oct 10, 2023
KEV Added Oct 18, 2023
Tracked Since Feb 18, 2026