logo

CVE-2022-27518 exploited in the wild by APT5: everything you need to know

ID: 869fa2e9-1773-5757-b964-4e23cf00744c

STIX ID: report--869fa2e9-1773-5757-b964-4e23cf00744c

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2022-12-13

Date Updated: 2026-05-01

...
...

**CVE-2022-27518** is a zero-day unauthenticated remote code execution vulnerability in Citrix ADC/Citrix Gateway that has been observed exploited in the wild by the China-attributed APT5; Citrix and the NSA published advisories and detection/hunting guidance, affected customers should update to patched builds or disable SAML, and exploitation is limited to customer-managed appliances with SAML SP/IdP configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.