Definition

CitrixBleed (CVE-2023-4966) is a critical session token leak vulnerability in Citrix NetScaler ADC/Gateway disclosed in 2023. Attackers exploited it in high-profile breaches (e.g., Boeing, Comcast) by harvesting authentication tokens to bypass MFA. The 2025 successor citrixbleed-2 (CVE-2025-5777) follows the same attack pattern.

Key Points

  • Pre-authentication buffer overread leaking session cookies from HTTP responses
  • Enabled MFA bypass via stolen authenticated sessions
  • Patched 2023; remains reference point for NetScaler session hygiene
  • Lineage continued with citrixbleed-2 active IAB exploitation in H1 2026

Sources