Citrix Vulnerabilities
Citrix is a Cloud Software Group company, and most of its KEV entries concern NetScaler ADC and NetScaler Gateway application delivery and remote access appliances. The database tracks 27 Citrix CVE records. CISA lists 27 of them as exploited in the wild, most recently on 2026-10-04. The most affected products are NetScaler, NetScaler ADC and NetScaler Gateway, Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance.
Recently Exploited Citrix CVEs
Memory overflow vulnerability leading to Denial of Service
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
Insufficient input validation leading to memory overread
Affected Products
12 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| NetScaler | 6 | 6 | 2026-10-04 |
| NetScaler ADC and NetScaler Gateway | 5 | 5 | 2026-08-26 |
| Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | 4 | 4 | 2021-11-03 |
| NetScaler ADC and Gateway | 2 | 2 | 2025-07-10 |
| SD-WAN and NetScaler | 2 | 2 | 2022-03-25 |
| Session Recording | 2 | 2 | 2025-08-25 |
| Application Delivery Controller (ADC) and Gateway | 1 | 1 | 2022-12-13 |
| Content Collaboration | 1 | 1 | 2023-08-16 |
| NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server | 1 | 1 | 2022-03-25 |
| ShareFile | 1 | 1 | 2022-03-25 |
| StoreFront Server | 1 | 1 | 2021-11-03 |
| Workspace Application and Receiver for Windows | 1 | 1 | 2021-11-03 |
Security Advisories
All Citrix CVEs
27 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-88779 | Memory overflow vulnerability leading to Denial of Service | NetScaler | 8.7 | 0.6% | KEV | 2026-10-04 |
| CVE-2026-88772 | Memory overflow vulnerability leading to Remote Code Execution or Denial of Service | Citrix NetScaler | 9.5 | 1.3% | KEV | 2026-09-27 |
| CVE-2026-88771 | A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands | Citrix NetScaler | 9.5 | 1.1% | KEV | 2026-09-27 |
| CVE-2026-19490 | NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 | NetScaler | 9.3 | 23.2% | KEV | 2026-08-19 |
| CVE-2026-8452 | Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service | NetScaler | 8.8 | 1.0% | KEV | 2026-06-30 |
| CVE-2026-3055 | Insufficient input validation leading to memory overread | NetScaler | 9.3 | 4.0% | KEV | 2026-03-23 |
| CVE-2025-7775 | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service | NetScaler | 9.2 | 20.3% | KEV | 2025-08-26 |
| CVE-2024-8069 | Limited remote code execution with privilege of a NetworkService Account access | Citrix Session Recording | 5.1 | 14.6% | KEV | 2024-11-12 |
| CVE-2024-8068 | Privilege escalation to NetworkService Account access | Citrix | 5.1 | 3.5% | KEV | 2024-11-12 |
| CVE-2025-5777 | NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread | NetScaler | 9.3 | 100.0% | KEV | 2025-06-17 |
| CVE-2025-6543 | Memory overflow vulnerability leading to unintended control flow and Denial of Service | NetScaler | 9.2 | 10.6% | KEV | 2025-06-25 |
| CVE-2023-6549 | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | Cloud Software Group | 8.2 | 57.6% | KEV | 2024-01-17 |
| CVE-2023-6548 | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | Cloud Software Group | 5.5 | 3.2% | KEV | 2024-01-17 |
| CVE-2023-4966 | Unauthenticated sensitive information disclosure | Citrix | 9.4 | 100.0% | KEV | 2023-10-10 |
| CVE-2023-24489 | Citrix Content Collaboration ShareFile Improper Access Control Vulnerability | Citrix | 9.8 | 97.3% | KEV | 2023-07-10 |
| CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | Citrix | 9.8 | 99.7% | KEV | 2023-07-19 |
| CVE-2022-27518 | Unauthenticated remote arbitrary code execution | Citrix | 9.8 | 6.7% | KEV | 2022-12-13 |
| CVE-2019-12989 | Citrix SD-WAN and NetScaler SQL Injection Vulnerability | - | 9.8 | 95.0% | KEV | 2019-07-16 |
| CVE-2019-12991 | Citrix SD-WAN and NetScaler Command Injection Vulnerability | - | 8.8 | 74.1% | KEV | 2019-07-16 |
| CVE-2017-6316 | Citrix Multiple Products Remote Code Execution Vulnerability | - | 9.8 | 73.0% | KEV | 2017-07-20 |
| CVE-2021-22941 | Citrix ShareFile Improper Access Control Vulnerability | - | 9.8 | 53.6% | KEV | 2021-09-23 |
| CVE-2019-19781 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability | - | 9.8 | 100.0% | KEV | 2019-12-27 |
| CVE-2020-8193 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability | - | 6.5 | 88.4% | KEV | 2020-07-10 |
| CVE-2020-8195 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability | - | 6.5 | 33.0% | KEV | 2020-07-10 |
| CVE-2019-13608 | Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability | - | 7.5 | 30.0% | KEV | 2019-08-29 |
| CVE-2020-8196 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability | - | 4.3 | 26.3% | KEV | 2020-07-10 |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability | - | 9.8 | 8.1% | KEV | 2019-05-22 |
Frequently Asked Questions
How many Citrix vulnerabilities are actively exploited?→
27 Citrix CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-10-04.
Which Citrix vulnerabilities are used in ransomware attacks?→
CISA marks 7 Citrix KEV entries as known to be used in ransomware campaigns, including CVE-2025-5777, CVE-2023-4966, CVE-2023-3519, CVE-2021-22941, CVE-2019-19781.
Which Citrix products have the most exploited vulnerabilities?→
- +NetScaler: 6 CVEs (6 in KEV)
- +NetScaler ADC and NetScaler Gateway: 5 CVEs (5 in KEV)
- +Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance: 4 CVEs (4 in KEV)
- +NetScaler ADC and Gateway: 2 CVEs (2 in KEV)
- +SD-WAN and NetScaler: 2 CVEs (2 in KEV)
Where does Citrix publish security advisories?→
Citrix publishes security advisories at https://support.citrix.com/securitybulletins. Check the vendor advisory for fixed versions and workarounds before applying updates.
Sources
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Citrix, MITRE, CISA, or FIRST.