LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-27518: Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 13, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 3, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-27518 to its Known Exploited Vulnerabilities catalog on Dec 13, 2022, with a federal patch deadline of Jan 3, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as…

CVE-2022-27518 is an authentication bypass vulnerability in Citrix Application Delivery Controller (ADC) and Gateway appliances when they are configured for SAML service provider (SP) or identity provider (IdP) roles. An attacker who can reach the vulnerable interface may bypass authentication and execute code with administrator privileges. Because these products commonly sit at the edge of enterprise networks and terminate remote-access and application-delivery traffic, successful exploitation can give an attacker a high-privilege foothold on a critical security gateway.

Organizations that run Citrix ADC or Gateway with SAML enabled should treat this as a high-priority issue and confirm their exact configuration and patch status against the vendor advisory.

How it works

The vulnerability is classified under CWE-664 (Improper Control of a Resource Through its Lifetime). In the SAML SP or IdP configuration path, the product fails to enforce proper authentication checks on certain requests. An unauthenticated attacker who can communicate with the affected service can therefore obtain an administrative session and run code with elevated privileges. Exact request formats and exploitation steps are not detailed here; defenders must consult the official Citrix advisory for technical indicators and any proof-of-concept restrictions.

Because the flaw is an authentication bypass that yields administrator-level code execution, the attacker does not need valid credentials once the vulnerable SAML configuration is present and reachable.

Am I affected? How to find it in your systems

Citrix ADC and Gateway appliances are typically deployed as physical or virtual appliances that provide load balancing, SSL VPN, reverse-proxy, and application-delivery functions. They often face the internet or sit in DMZ segments.

If the appliance is not configured for SAML SP or IdP, the exposure described by CISA does not apply, but you should still verify the configuration and keep the device patched.

How to remediate

The primary remediation is to apply the updates published by Citrix for this vulnerability. Follow the vendor’s installation and reboot guidance exactly; CISA’s required action is simply “Apply updates per vendor instructions.”

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These steps lower risk but do not eliminate the vulnerability; plan to patch as soon as possible.

If your data may have been exposed

Actively exploited authentication-bypass flaws on edge gateways frequently lead to further compromise of internal systems and data. If you discover evidence of exploitation, treat the incident as a potential breach: isolate the appliance, preserve forensic logs, rotate credentials that may have been accessible, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether any of your accounts already appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCitrix · Application Delivery Controller (ADC) and Gateway
WeaknessCWE-664
Added to CISA KEVDec 13, 2022
Federal patch deadlineJan 3, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities