Definition
CitrixBleed (CVE-2023-4966) is a critical session token leak vulnerability in Citrix NetScaler ADC/Gateway disclosed in 2023. Attackers exploited it in high-profile breaches (e.g., Boeing, Comcast) by harvesting authentication tokens to bypass MFA. The 2025 successor citrixbleed-2 (CVE-2025-5777) follows the same attack pattern.
Key Points
- Pre-authentication buffer overread leaking session cookies from HTTP responses
- Enabled MFA bypass via stolen authenticated sessions
- Patched 2023; remains reference point for NetScaler session hygiene
- Lineage continued with citrixbleed-2 active IAB exploitation in H1 2026