Researchers analyzing CVE-2023-3519, the critical Citrix ADC and NetScaler Gateway vulnerability previously reported as exploited in the wild, identified pre-authentication memory-corruption conditions in SAML/SSO-related request handling. Patch-diff analysis indicated that unpatched SAML parsing lacks a bounds check on CanonicalizationMethod values processed by ns_aaa_saml_parse_authn_request, enabling an out-of-bounds write; testing demonstrated crashes and memory corruption, though the researchers did not achieve arbitrary remote code execution. The affected parsing path appeared reachable when SAML/SSO is enabled, while other pre-authentication paths may also exist.
A separate analysis found that the /gwtest/formssso endpoint can crash when supplied with event=start or event=stop and an oversized URL-encoded target parameter. The patched code restricts the parameter to fewer than 0x80 bytes before decoding, whereas the unpatched code lacks that check; researchers demonstrated instruction-pointer control but not command execution. Organizations should apply Citrix fixes for CVE-2023-3519 and related Citrix ADC/Gateway issues, review CISA compromise indicators, and assess exposed appliances; HTTP 500 responses alone are not a reliable indicator because they can occur on both patched and unpatched systems.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
An exploit for CVE-2023-3519 was reportedly offered for sale online beginning in June 2023.
Researchers reported that an oversized URL-encoded target parameter sent to /gwtest/formssso with event=start or event=stop could crash unpatched Citrix ADC and NetScaler Gateway appliances. They demonstrated instruction-pointer control by redirecting execution to stack-resident INT3 instructions; patched code enforces a decoded-input limit below 0x80 bytes.
Patch-diff analysis identified a suspected out-of-bounds write in Citrix's SAML parser: unpatched code allegedly failed to bound CanonicalizationMethod values stored in a fixed array. Researchers demonstrated crashes and memory corruption, and developed a malformed-SAML error-oracle method to distinguish patched, unpatched, and SAML-disabled systems.
Citrix issued an advisory and patches for CVE-2023-3519, a critical remote-code-execution vulnerability affecting Citrix ADC and NetScaler Gateway that was reportedly exploited in the wild.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
slcyber.io
Open sourceslcyber.io
Open sourcesupport.citrix.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.