China-attributed APT5 actively exploited CVE-2022-27518, a critical Citrix ADC and Citrix Gateway flaw that lets an unauthenticated remote attacker execute arbitrary code and bypass authentication controls. The activity prompted a joint U.S. government cybersecurity advisory detailing threat-hunting guidance and indicators associated with exploitation.
The vulnerability affects customer-managed Citrix appliances configured as a SAML service provider or SAML identity provider; Citrix ADC and Citrix Gateway 13.1 are not affected. Organizations should urgently apply Citrix’s security updates, disable SAML authentication where operationally feasible until remediation is complete, and hunt for the published indicators of compromise.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
The NSA warned that China-attributed APT5 was actively exploiting CVE-2022-27518 in the wild. The flaw enables unauthenticated remote code execution and authentication bypass on affected Citrix ADC and Gateway appliances configured for SAML functionality.
Citrix advised customers using affected customer-managed Citrix ADC and Citrix Gateway appliances to update to fixed releases, including 12.1-65.25 or 13.0-88.16. It also recommended disabling SAML authentication where prompt updating was not feasible.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.