# Citrix ADC/Gateway RCE exploited in wild

Published: 2022-12-13 · Severity: high · Sectors: technology, government-national
Canonical: https://vorant.io/reports/387c2d0b-405b-5911-abd3-083006fec469/citrix-adc-gateway-rce-exploited-in-wild

> An unauthenticated remote code execution flaw in Citrix ADC and Gateway configured as SAML SP/IdP is being actively exploited, IPA Japan warns.

IPA Japan issued an alert regarding a remote code execution vulnerability affecting Citrix ADC and Citrix Gateway appliances, which are commonly used to build enterprise network infrastructure. The flaw allows an unauthenticated remote attacker to execute arbitrary code on affected devices, but only impacts instances configured as a SAML Service Provider (SP) or SAML Identity Provider (IdP).

The advisory confirms that exploitation of this vulnerability has already been observed in the wild, with the potential for damage to expand further. This matches the profile of CVE-2022-27518, a Citrix ADC/Gateway vulnerability disclosed and patched in December 2022 that was reportedly exploited by a state-sponsored actor prior to patch availability. IPA urges administrators to verify their SAML SP/IdP configuration status per Citrix's guidance and apply the vendor's security updates immediately given the confirmed in-the-wild exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2022-27518 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/alert20221214.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/387c2d0b-405b-5911-abd3-083006fec469/citrix-adc-gateway-rce-exploited-in-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
