criticalKEV
CVE-2023-4966
Citrix Bleed: sensitive session-token disclosure
- Severity
- critical
- Affected product
- Citrix NetScaler ADC/Gateway
- Affected versions
- Citrix NetScaler ADC/Gateway < 14.1
- Fixed in
- Citrix NetScaler ADC/Gateway 14.1-8.50
- CISA KEV
- Listed as a known exploited vulnerability
- EPSS
- 96% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-07-13
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Citrix NetScaler ADC/Gateway appliance and reports this CVE when the detected version falls inside the affected range below.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →