NetScaler ADC and Gateway
CVE-2022-27518: Unauthenticated remote arbitrary code execution
Unauthenticated remote arbitrary code execution
Published
ExploitedYes, in CISA KEVAdded 13 Dec 2022
Ransomware useNot reportedPer CISA
SeverityCRITICALCVSS 3.1 9.8
EPSS6.7%Chance of exploitation in 30 days
Public exploitNot tracked
FixNot yet
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Citrix Gateway, Citrix ADC 12.1 | See the advisory |
| Citrix Gateway, Citrix ADC 13.0 | See the advisory |
| Citrix Gateway, Citrix ADC 12.1 FIPs, NDcPP | See the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
Unauthenticated remote arbitrary code execution
Exploitation
CISA lists this CVE as exploited in the wild since 13 Dec 2022.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.