KNOWN EXPLOITED VULNERABILITY DOSSIER

CVE-2023-4966

Citrix · NetScaler ADC and Gateway

Sensitive information disclosure vulnerability ('Citrix Bleed') allowing unauthenticated session token hijacking exploited by LockBit 3.0 affiliates.

CISA KEV Added: 2023-10-18
Severity Rating: Critical (CVSS 9.4)
Legal Indictments: 1 Case
Catalog Status: Active KEV Mandate

Correlated Federal Court Cases & Indictments (1)

Associated Government Advisories

← Back to All CVEs Explore ATT&CK Matrix →