July 19, 2023 · Applied Cybernetics Group
CVE-2023-3519 — Citrix NetScaler ADC and NetScaler Gateway
known ransomware use
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
- Added to KEV
2023-07-19- Federal due date
2023-08-09- Vendor
- Citrix
- Product
- NetScaler ADC and NetScaler Gateway
- EPSS
- 100.0th percentile (score 0.997, as of
2026-09-16) - NVD CVSS v3.1
- 9.8 (CRITICAL)
- Ransomware use
- Known
- ATT&CK
- T1087.002 , T1105 , T1190 , T1574 · signal rollup
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2023-3519
CISA short description
Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
NVD description
Unauthenticated remote code execution