# Citrix Bleed, session-token leak from NetScaler ADC

Source: https://startwithidentity.com/cves/cve-2023-4966/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

NetScaler ADC and Gateway (the Citrix ADC/Gateway pair) would over-read a buffer and return memory that contained live session cookies. An unauthenticated caller harvested tokens and replayed them. MFA on the original login did not matter. The session already existed. CISA added CVE-2023-4966 to KEV. Public name: Citrix Bleed. October 2023.

## Why it matters

This is [session hijacking](https://startwithidentity.com/glossary/session-hijacking/) as a product bug, not a stolen laptop. Identity teams who measure success as "MFA is on" learned that a gateway cookie is a bearer credential. The same lesson shows up later in [Pass-the-Passkey](https://startwithidentity.com/cves/cve-2026-34348/) and in our [infostealer teardown](https://startwithidentity.com/breaches/infostealer-session-hijacking/).

## What to do

- Patch ADC/Gateway, then *terminate all sessions*. A patched box with live leaked cookies is still owned.
- Hunt for sessions that have no matching interactive login, especially from new ASNs after 10 October 2023.
- Bind gateway sessions to a device or client where the product allows it. Shorten idle timeouts.

## After you patch

Edge appliances sit outside the estate and hold credentials into it, which is why this class keeps producing multi-victim campaigns.

- **Revoke all sessions on the appliance**, then rotate the directory or [LDAP](https://startwithidentity.com/glossary/federation/) service account it uses for authentication.
- **Rotate certificates and any stored integration credentials**, since configuration stores on these devices are a routine post-exploitation target.
- **Hunt for authenticated sessions with no matching interactive login**, and for logins from ASNs that had never appeared before the disclosure date.
- **Check downstream**: anything the appliance could reach or authenticate to is in scope, including [SSO](https://startwithidentity.com/glossary/sso/)-connected applications.

## Sources

- [NVD: CVE-2023-4966](https://nvd.nist.gov/vuln/detail/CVE-2023-4966)
- CISA KEV / Citrix Bleed advisories, October 2023
