
Passively fingerprint Citrix ADC / NetScaler ADC & Gateway builds and detect known CVEs — CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and CVE-2026-88771/88772 (KEV)
citrixInspector.py (formerly cve_2023_3519_inspector.py) is a Python-based, passive vulnerability
scanner for Citrix ADC / Citrix Gateway / NetScaler ADC / NetScaler Gateway appliances. It fingerprints
the exact firmware build of a target without authentication, and reports every known CVE that build is
vulnerable to.
⚠️ Beta: Detection for the newer 2025/2026 CVEs (CitrixBleed 2/3, CVE-2026-8452, CVE-2026-88771/88772) is in beta. It relies on being able to fingerprint the exact firmware build via the GZIP-timestamp or vhash techniques; when neither works on a target, the scanner falls back to a much coarser, CVE-2023-3519-only heuristic and will not flag the newer CVEs at all (see the Checks Performed section below). Treat results for the newer CVEs as informational only.

Output was run against a simulated test harness. Hostname is a placeholder only.
cve_2023_3519_inspector.py to citrixInspector.py to reflect its broader, multi-CVE scope./vpn/js/rdx/core/lang/rdx_en.json.gz) as the primary,
most reliable unauthenticated build-identification technique, since the legacy v=<hash> static
resource hash is "not always present anymore" on modern builds.Last-Modified header) with a
precise version-threshold comparison whenever an exact build is known, falling back to the original
heuristic only when no build can be identified.This script requires Python 3.6+ and the following Python packages:
To install the required packages, run:
git clone https://github.com/securekomodo/citrixInspector.git
cd citrixInspector
pip install -r requirements.txt
python citrixInspector.py -u <target_url>
Author: Bryan Smith (@securekomodo)
------------------------
_________ .__ __ .__
\_ ___ \|__|/ |________|__|__ ___
/ \ \/| \ __\_ __ \ \ \/ /
\ \___| || | | | \/ |> <
\______ /__||__| |__| |__/__/\_ \
\/ \/
.___ __
| | ____ ____________ ____ _____/ |_ ___________
| |/ \ / ___/\____ \_/ __ \_/ ___\ __\/ _ \_ __ \
| | | \___ \ | |_> > ___/\ \___| | ( <_> ) | \/
|___|___| /____ >| __/ \___ >\___ >__| \____/|__|
\/ \/ |__| \/ \/
citrixInspector
------------------------
usage: citrixInspector.py [-h] (-u URL | -f FILE) [--ioc-check] [-l LOG]
Fingerprint and check Citrix ADC / NetScaler ADC & Gateway for known CVEs.
optional arguments:
-h, --help show this help message and exit
-u URL, --url URL The URL of the Citrix/NetScaler Gateway to check.
-f FILE, --file FILE A file containing a list of URLs to check.
--ioc-check Slower. Performs IOC (Indicator of Compromise) check.
-l LOG, --log LOG Log file to write the output.
The citrixInspector.py script can either accept a single URL or a file with a list of URLs as input. It then performs a series of checks to determine the potential vulnerability of the given Citrix/NetScaler Gateways:
# Check a single URL
python citrixInspector.py --url https://example.com
# Check multiple URLs from a file
python citrixInspector.py --file urls.txt
# Check multiple URLs from a file and check for IOCs
python citrixInspector.py --file urls.txt --ioc-check
To specify a log file for output, use the --log option:
python citrixInspector.py --url https://example.com --log my_log.log
For help:
python citrixInspector.py --help
The citrixInspector.py script performs the following checks on the target websites:
MTIME header field (RFC 1952)
of /vpn/js/rdx/core/lang/rdx_en.json.gz, which is set at firmware compile time and uniquely
identifies the exact build. This is the current recommended technique from the Fox-IT Security
Research Team, since the vhash technique below "is not always present anymore" on modern builds.v=<md5>
hashes in static resource URLs embedded in the HTML content. This is based off the amazing work
from Fox-IT (NCC Group) back in 2022:
https://blog.fox-it.com/2022/12/28/cve-2022-27510-cve-2022-27518-measuring-citrix-adc-gateway-version-adoption-on-the-internet/Whenever an exact build can be identified (via the GZIP-timestamp check, the vhash check, or
pluginlist.xml), the script checks that build against every CVE in the table below and reports all
that apply ([CERTAIN]). When no exact build can be identified, it falls back to the original
title/icon/comment/header heuristics ([FIRM] / [TENTATIVE] / [CITRIX DETECTED]), scoped only to
CVE-2023-3519 as before.
| CVE | Description | Fixed in |
|---|---|---|
| CVE-2023-3519 | Unauthenticated RCE (stack overflow) | 13.0-91.13 / 13.1-49.13 |
| CVE-2025-5349 / CVE-2025-5777 | "CitrixBleed 2" - memory disclosure | 14.1-43.56 / 13.1-58.32 |
| CVE-2025-6543 | Memory overflow (Gateway), exploited in the wild | 14.1-47.46 / 13.1-59.19 |
| CVE-2025-7775 / CVE-2025-7776 / CVE-2025-8424 | "CitrixBleed 3" | 14.1-47.48 / 13.1-59.22 |
| CVE-2026-8452 | Pre-auth SAML PrefixList heap overflow (requires SAML SP/IdP config) | 14.1-72.61 / 13.1-63.18 |
| CVE-2026-88771 / CVE-2026-88772 | Pre-auth command injection / DTLS memory overflow — actively exploited, in CISA KEV | 14.1-73.37 / 13.1-64.23 |
All branches that reached End-Of-Life before a fix was released (11.1, 12.1 non-FIPS/NDcPP, 13.0) are reported as vulnerable to every CVE above. FIPS/NDcPP builds (12.1-55.x, 13.1-37.x) are checked against their own, separately-published fix builds.