Citrix ADC/Gateway RCE exploited in wild
An unauthenticated remote code execution flaw in Citrix ADC and Gateway configured as SAML SP/IdP is being actively exploited, IPA Japan warns.
IPA Japan issued an alert regarding a remote code execution vulnerability affecting Citrix ADC and Citrix Gateway appliances, which are commonly used to build enterprise network infrastructure. The flaw allows an unauthenticated remote attacker to execute arbitrary code on affected devices, but only impacts instances configured as a SAML Service Provider (SP) or SAML Identity Provider (IdP).
The advisory confirms that exploitation of this vulnerability has already been observed in the wild, with the potential for damage to expand further. This matches the profile of CVE-2022-27518, a Citrix ADC/Gateway vulnerability disclosed and patched in December 2022 that was reportedly exploited by a state-sponsored actor prior to patch availability. IPA urges administrators to verify their SAML SP/IdP configuration status per Citrix's guidance and apply the vendor's security updates immediately given the confirmed in-the-wild exploitation.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/alert20221214.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free