CVE-2023-4966
KEV RANSOMWARECRITICAL 9.4EPSS 100.0%
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 9.4 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2023-10-18, used in ransomware campaigns
- Nuclei
- high
- Published
- 2023-10-10
- Updated
- 2026-07-31
Proof-of-concept exploits (17)
- http://packetstormsecurity.com/files/175323/Citrix-Bleed-Session-Token-Leakage-Proof-Of-C…
- 0xKayala/CVE-2023-49660★ · 2023-10-28
- CerTusHack/Citrix-bleed-Xploit2★ · 2023-11-30
- Chocapikk/CVE-2023-496680★ · 2023-10-26
- IceBreakerCode/CVE-2023-49661★ · 2023-10-25
- LucasOneZ/CVE-2023-49660★ · 2024-09-14
- RevoltSecurities/CVE-2023-496610★ · 2023-10-29
- akshthejo/CVE-2023-4966-exploit0★ · 2025-01-17
- byte4RR4Y/CVE-2023-49660★ · 2023-11-27
- dinosn/citrix_cve-2023-496611★ · 2023-10-25
- jmussmann/cve-2023-4966-iocs0★ · 2023-12-09
- mingshenhk/CitrixBleed-2-CVE-2025-5777-PoC-17★ · 2025-06-30
- mlynchcogent/CVE-2023-4966-POC8★ · 2023-10-25
- morganwdavis/overread2★ · 2023-12-31
- prnvv2/ZeroSploit0★ · 2025-07-18
- s-bt/CVE-2023-49660★ · 2023-11-20
- sanjai-AK47/CVE-2023-496610★ · 2023-10-29