December 13, 2022 · Applied Cybernetics Group
CVE-2022-27518 — Citrix Application Delivery Controller (ADC) and Gateway
Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability
- Added to KEV
2022-12-13- Federal due date
2023-01-03- Vendor
- Citrix
- Product
- Application Delivery Controller (ADC) and Gateway
- EPSS
- 96.5th percentile (score 0.277, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-27518
CISA short description
Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.
Required action
Apply updates per vendor instructions.