---
title: Citrix Zero-Day Vulnerability Update
description: "On Oct 10, 2023, Citrix released a security bulletin for two previously unknown zero-day vulnerabilities: CVE-2023-4966 and CVE-2023-4967. These vulnerabilities affect the NetScaler ADC and NetScaler Gateway products."
image: https://www.irongatesecurity.com/hubfs/1%20(2).png
---

[Skip to the main content.](https://www.irongatesecurity.com/ironintel/citrix-zero-day-vulnerability-update#main-content)

[![Plexos\_IronGate\_Logo\_Final-2](https://www.irongatesecurity.com/hs-fs/hubfs/Plexos_IronGate_Logo_Final-2.png?width=1246&height=190&name=Plexos_IronGate_Logo_Final-2.png "Plexos_IronGate_Logo_Final-2")](https://www.irongatesecurity.com)

[![Plexos\_IronGate\_Logo\_Final-2](https://www.irongatesecurity.com/hs-fs/hubfs/Plexos_IronGate_Logo_Final-2.png?width=1246&height=190&name=Plexos_IronGate_Logo_Final-2.png "Plexos_IronGate_Logo_Final-2")](https://www.irongatesecurity.com)

- [Who We Are](https://www.irongatesecurity.com/who-we-are) 
    - [Our Leaders](https://www.irongatesecurity.com/who-we-are#our-leaders)
- [Services](https://www.irongatesecurity.com/services) 
    - [Active Defense](https://www.irongatesecurity.com/active-defense) 
          - [Governance, Risk & Compliance](https://www.irongatesecurity.com/governance-risk-compliance)
          - [Security Operation (SecOps) Services](https://www.irongatesecurity.com/security-operation-services)
    - [Digital Forensics and Incident Response (DFIR)](https://www.irongatesecurity.com/digital-forensics-incident-response)
    - [Insurance Advisory Services](https://www.irongatesecurity.com/insurance-advisory-services)
- [Why IronGate](https://www.irongatesecurity.com/why-irongate)
- [How We Work](https://www.irongatesecurity.com/how-we-work)
- Resources 
    - [IronINTEL Blog](https://www.irongatesecurity.com/ironintel)
    - [Careers](https://www.irongatesecurity.com/careers)

[![CONTACT US](https://no-cache.hubspot.com/cta/default/43428275/interactive-129984586382.png)](https://www.irongatesecurity.com/hs/cta/wi/redirect?encryptedPayload=AVxigLJEU7MUFumzl80iYh1bMniAKcVOFJPk7L5LvjNBK5bAqzkb8rUyyUdh2lQhzCp82GfX9CxcF4AyqIw7XpJ2JrpBuP4RlhytrWsujWNsP2RqBu%2FAMWtGkrycRq6YEDkBgskulznfiNlvuUUfROcLoIeqdXmRaIlZt7TSH%2BF2DcmenCTQUehhai3ee3LEwmKsWXdYB3F2KQ%3D%3D&webInteractiveContentId=129984586382&portalId=43428275)

Toggle Menu

Toggle Menu

[![CONTACT US](https://no-cache.hubspot.com/cta/default/43428275/interactive-129984586382.png)](https://www.irongatesecurity.com/hs/cta/wi/redirect?encryptedPayload=AVxigLJEU7MUFumzl80iYh1bMniAKcVOFJPk7L5LvjNBK5bAqzkb8rUyyUdh2lQhzCp82GfX9CxcF4AyqIw7XpJ2JrpBuP4RlhytrWsujWNsP2RqBu%2FAMWtGkrycRq6YEDkBgskulznfiNlvuUUfROcLoIeqdXmRaIlZt7TSH%2BF2DcmenCTQUehhai3ee3LEwmKsWXdYB3F2KQ%3D%3D&webInteractiveContentId=129984586382&portalId=43428275)

- [Who We Are *Toggle Menu*](https://www.irongatesecurity.com/who-we-are) 
    - [Our Leaders](https://www.irongatesecurity.com/who-we-are#our-leaders)
- [Services *Toggle Menu*](https://www.irongatesecurity.com/services) 
    - [Active Defense *Toggle Menu*](https://www.irongatesecurity.com/active-defense) 
          - [Governance, Risk & Compliance](https://www.irongatesecurity.com/governance-risk-compliance)
          - [Security Operation (SecOps) Services](https://www.irongatesecurity.com/security-operation-services)
    - [Digital Forensics and Incident Response (DFIR)](https://www.irongatesecurity.com/digital-forensics-incident-response)
    - [Insurance Advisory Services](https://www.irongatesecurity.com/insurance-advisory-services)
- [Why IronGate](https://www.irongatesecurity.com/why-irongate)
- [How We Work](https://www.irongatesecurity.com/how-we-work)
- Resources
  
  *Toggle Menu* 
  
    - [IronINTEL Blog](https://www.irongatesecurity.com/ironintel)
    - [Careers](https://www.irongatesecurity.com/careers)

 1 min read

# Citrix Zero-Day Vulnerability Update

[![Picture of IronGate](https://www.irongatesecurity.com/hubfs/IronGate%20Favicon.png) IronGate](https://www.irongatesecurity.com/ironintel/author/irongate)  Nov 15, 2023, 12:29:20 PM

![Citrix Zero-Day Vulnerability Update](https://www.irongatesecurity.com/hubfs/1%20(2).png)

## Take these important actions now to mitigate vulnerabilities in NetScaler ADC and NetScaler Gateway products

On Oct 10, 2023, [Citrix released a security bulletin](https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967) for two previously unknown zero-day vulnerabilities: CVE-2023-4966 and CVE-2023-4967. These vulnerabilities affect the NetScaler ADC and NetScaler Gateway products. When exploited, they allow an attacker to take over an active session, effectively impersonating a trusted user.

Citrix recommends the following actions to mitigate the vulnerabilities:

1. Kill all active sessions to the NetScaler ADC and Gateway products.
2. Immediately upgrade vulnerable products to unimpacted versions.

In addition to performing the recommended actions from Citrix, potentially impacted organizations should take the following precautions as part of their incident response process:

*Note: The following response steps should be performed before upgrading the vulnerable products to avoid overwriting pertinent artifacts. Once the artifacts are preserved, continue with upgrading the vulnerable products.*

1. Preserve log and appliance information: 
     1. Create a snapshot of the NetScaler products including its memory.
     2. Preserve log information from the NetScaler products, Web Application Firewalls, Load Balancers, and any other devices in front of the NetScaler products.
2. Review logs for abnormal web requests originating from suspicious IP addresses. 
     1. Geolocate IP addresses to determine if non-authorized users attempted connection.
     2. Look for requests to ‘oauth/idp/.well-known/openid-configuration’ or other configuration and administration URLs.
     3. Correlate sessions to IP addresses to identify if a single session has more than one associated IP address.
3. Depending on the above findings, additional forensic analysis may be necessary to examine internal host systems to identify additional post-exploitation activity.

Additional steps for mitigation if abnormal access is identified:

- Consider changing all NetScaler ADC and Gateway passwords.
- Revoke and reissue SSL certificates.
- Change Active Directory NetScaler account passwords.
- Consider performing a user account audit of Active Directory.

Additional Resources

- [NetScaler instructions to kill all sessions](https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/)
- [NIST CVE-2023-4966 Detail](https://nvd.nist.gov/vuln/detail/CVE-2023-4966)
- [NIST CVE-2023-4967 Detail](https://nvd.nist.gov/vuln/detail/CVE-2023-4967)
- [CISA Guidance on CVE-2023-4966](https://www.cisa.gov/guidance-addressing-citrix-netscaler-adc-and-gateway-vulnerability-cve-2023-4966-citrix-bleed)

---

Check out IronGate’s Digital Forensics and Incident Response capabilities:

[![LEARN MORE](https://no-cache.hubspot.com/cta/default/43428275/interactive-134473575199.png)](https://www.irongatesecurity.com/hs/cta/wi/redirect?encryptedPayload=AVxigLKqopVQR5s6r0CjNjS60t5n52xzqzdC1wkv2I2izbt%2BsoeffaEN4UTX2bbi7Gai7KkvuFCkxGJcTSFCCTlEUjTs0I9FXlfcTaXvIZ8ggph4NLSB9KtXmEDV%2BCY7CmRmIJXRmP%2FIkYpF6dBOGbaNORdJ9yoBI6HXA7wwSDIO%2Fs5mnhYGXKSM0LqGdvmZk0S%2BVYlsuTVmYUf%2BkxsmclRqPaVKJLwOTgdsb74rKHlOUo6ETpY%3D&webInteractiveContentId=134473575199&portalId=43428275)

| ![Marra](https://www.irongatesecurity.com/hs-fs/hubfs/Marra.png?width=276&height=276&name=Marra.png) | [Joseph Marra](https://www.irongatesecurity.com/joseph-marra) brings over 10 years of experience in the cybersecurity industry with a key focus on ransomware investigations, business email compromise, advanced persistent threat intrusions, and insider threat investigations. Joseph has played a vital role in contributing to the foundation of multiple forensic labs and incident response infrastructures. |
| --- | --- |

 

<https://www.irongatesecurity.com/>

[![ConnectWise Vulnerability Update](https://www.irongatesecurity.com/hubfs/ConnectWise.jpg)](https://www.irongatesecurity.com/ironintel/connectwise-vulnerability-update)

#### [ConnectWise Vulnerability Update](https://www.irongatesecurity.com/ironintel/connectwise-vulnerability-update)

[![Picture of IronGate](https://www.irongatesecurity.com/hs-fs/hubfs/IronGate%20Favicon.png?width=30&name=IronGate%20Favicon.png) IronGate](https://www.irongatesecurity.com/ironintel/author/irongate) : Feb 26, 2024, 9:42:24 AM

On February 19, 2024, ConnectWise released a security bulletin reporting two vulnerabilities: CVE-2024-1709 and CVE-2024-1708. Both vulnerabilities...

[Read More](https://www.irongatesecurity.com/ironintel/connectwise-vulnerability-update)

[![IronCORE Recon 2026-04-24](https://www.irongatesecurity.com/hubfs/ChatGPT%20Image%20Mar%2013%2c%202026%2c%2010_08_54%20AM.png)](https://www.irongatesecurity.com/ironintel/ironcore-recon-2026-04-24)

#### [IronCORE Recon 2026-04-24](https://www.irongatesecurity.com/ironintel/ironcore-recon-2026-04-24)

[![Picture of IronGate](https://www.irongatesecurity.com/hs-fs/hubfs/IronGate%20Favicon.png?width=30&name=IronGate%20Favicon.png) IronGate](https://www.irongatesecurity.com/ironintel/author/irongate) : Apr 24, 2026, 9:06:03 AM

Adversaries are shifting focus from endpoints to infrastructure and identity controls, creating new vulnerabilities that demand immediate attention...

[Vulnerability](https://www.irongatesecurity.com/ironintel/tag/vulnerability) [Ransomware](https://www.irongatesecurity.com/ironintel/tag/ransomware) [IronCORE Recon](https://www.irongatesecurity.com/ironintel/tag/ironcore-recon) [AI](https://www.irongatesecurity.com/ironintel/tag/ai) [Zero-Day](https://www.irongatesecurity.com/ironintel/tag/zero-day) [Edge](https://www.irongatesecurity.com/ironintel/tag/edge)

[Read More](https://www.irongatesecurity.com/ironintel/ironcore-recon-2026-04-24)

[![IronCORE Recon 2026-04-10](https://www.irongatesecurity.com/hubfs/ChatGPT%20Image%20Mar%2013%2c%202026%2c%2010_08_54%20AM.png)](https://www.irongatesecurity.com/ironintel/ironcore-recon-2026-04-10)

#### [IronCORE Recon 2026-04-10](https://www.irongatesecurity.com/ironintel/ironcore-recon-2026-04-10)

[![Picture of IronGate](https://www.irongatesecurity.com/hs-fs/hubfs/IronGate%20Favicon.png?width=30&name=IronGate%20Favicon.png) IronGate](https://www.irongatesecurity.com/ironintel/author/irongate) : Apr 13, 2026, 9:44:14 AM

Explore the evolving threat landscape where adversaries target infrastructure and trust mechanisms, leveraging AI to accelerate attacks and exploit...

[Vulnerability](https://www.irongatesecurity.com/ironintel/tag/vulnerability) [Ransomware](https://www.irongatesecurity.com/ironintel/tag/ransomware) [IronCORE Recon](https://www.irongatesecurity.com/ironintel/tag/ironcore-recon) [AI](https://www.irongatesecurity.com/ironintel/tag/ai) [Edge](https://www.irongatesecurity.com/ironintel/tag/edge)

[Read More](https://www.irongatesecurity.com/ironintel/ironcore-recon-2026-04-10)

 

![Plexos\_IronGate\_Logo\_Final-2](https://www.irongatesecurity.com/hs-fs/hubfs/Plexos_IronGate_Logo_Final-2.png?width=301&height=46&name=Plexos_IronGate_Logo_Final-2.png)

![Irongate\_Award\_Logos](https://www.irongatesecurity.com/hs-fs/hubfs/Irongate_Award_Logos.png?width=557&height=210&name=Irongate_Award_Logos.png)

 

- [Privacy Policy](https://www.irongatesecurity.com/privacy-policy)
- [Terms of Use](https://www.irongatesecurity.com/terms-of-use)
- [Your Privacy Choices ![](https://www.irongatesecurity.com/hubfs/privacyoptions.png)](https://www.irongatesecurity.com/your-privacy-choices)

© 2026 IronGate Cybersecurity LLC

[*LinkedIn*](https://www.linkedin.com/company/irongate-cybersecurity-llc/?lipi=urn%3Ali%3Apage%3Ad_flagship3_search_srp_companies_load_more%3BcMuuS27qSPaVn%2BG%2BihNnZw%3D%3D)

*Return to Top*

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "IronGate",
    "url" : "https://www.irongatesecurity.com/ironintel/author/irongate"
  },
  "dateModified" : "2023-11-15T17:29:20.907Z",
  "datePublished" : "2023-11-15T17:29:20.000Z",
  "headline" : "Citrix Zero-Day Vulnerability Update",
  "image" : [ "https://www.irongatesecurity.com/hubfs/1%20(2).png" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.irongatesecurity.com/ironintel/citrix-zero-day-vulnerability-update",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.irongatesecurity.com/hubfs/Plexos_IronGate_Logo_Final-1.png"
    },
    "name" : "IronGate Cybersecurity LLC"
  }
}
```