Known exploited / historically exploited security risk
CVE-2023-4966 — NetScaler ADC / NetScaler Gateway
A vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway that can expose session information and enable authenticated session hijacking. CISA reported exploitation activity and added it to the Known Exploited Vulnerabilities catalog.
Business relevance
If NetScaler ADC / NetScaler Gateway is present in your environment, confirm whether the installed version and configuration are affected. The existence of this CVE does not by itself prove that a specific system is vulnerable or compromised.
What to check
- Identify any NetScaler ADC or NetScaler Gateway appliances.
- Record the exact software version and deployment role.
- Confirm vendor-supported remediation has been applied.
- Review for evidence of session compromise where applicable.
Source record
Authoritative source: CISA joint cybersecurity advisory and Known Exploited Vulnerabilities program.
CompFlorida record reviewed: September 21, 2026.
Vendor: Citrix
Product: NetScaler ADC / NetScaler Gateway
CVE: CVE-2023-4966
Need help checking applicability?
CompFlorida can help identify the product/version in use, review exposure and coordinate the appropriate remediation path.
Request a Technology Risk Review
