Brand
Citrix: actively exploited vulnerabilities
26 vulnerabilities in Citrix products (NetScaler ADC / Gateway, SD-WAN, Session Recording…) are in CISA’s catalog of exploited vulnerabilities, 4 of them added in the last 90 days. Last added: September 27, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
5 vulnerabilities added in the last 12 months
-
26 exploited vulnerabilities in the catalog, in total
-
3 added in the last 30 days
By category
Add just one Citrix category to your radar, or open its page.
- Load balancers and access gateways (ADC) 17 vulnerabilities
- Virtualization, VDI and cloud 4 vulnerabilities
- Switches, routers and SD-WAN 3 vulnerabilities
- Managed file transfer (MFT) 2 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
Follow a single Citrix product (NetScaler ADC / Gateway, SD-WAN…) rather than the whole brand.
- NetScaler ADC / Gateway17 vulnerabilities, ADCs
- SD-WAN3 vulnerabilities, Switches and routers
- Session Recording2 vulnerabilities, Virtualization and VDI
- ShareFile2 vulnerabilities, File transfer (MFT)
- StoreFront1 vulnerability, Virtualization and VDI
- Workspace app / Receiver1 vulnerability, Virtualization and VDI
Name used by CISA: Citrix. Product families: indicative classification by this site.
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 9, 2025 to Oct 8, 2025 | 0 |
| Oct 9, 2025 to Nov 7, 2025 | 0 |
| Nov 8, 2025 to Dec 7, 2025 | 0 |
| Dec 8, 2025 to Jan 6, 2026 | 0 |
| Jan 7, 2026 to Feb 5, 2026 | 0 |
| Feb 6, 2026 to Mar 7, 2026 | 0 |
| Mar 8, 2026 to Apr 6, 2026 | 1 |
| Apr 7, 2026 to May 6, 2026 | 0 |
| May 7, 2026 to Jun 5, 2026 | 0 |
| Jun 6, 2026 to Jul 5, 2026 | 0 |
| Jul 6, 2026 to Aug 4, 2026 | 0 |
| Aug 5, 2026 to Sep 3, 2026 | 1 |
| Sep 4, 2026 to Oct 3, 2026 (in progress) | 3 |
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Citrix list.
- Rank 1
Citrix NetScaler ADC / GatewayCVE-2026-88771
Citrix NetScaler Improper Input Validation Vulnerability
Recently addedActive CERT-FR alertHunt for compromise (CISA)
CVSS severity 9.8critical
Added Sep 27, 2026
- Rank 2
Citrix NetScaler ADC / GatewayCVE-2026-88772
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Recently addedActive CERT-FR alertHunt for compromise (CISA)
CVSS severity 8.1high
Added Sep 27, 2026
- Rank 3
Citrix NetScaler ADC / GatewayCVE-2026-19490
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Recently addedHunt for compromise (CISA)
CVSS severity 9.8critical
Added Sep 9, 2026
- Rank 4
Citrix NetScaler ADC / GatewayCVE-2026-8452
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
CVSS severity 9.8critical
Added Aug 26, 2026
- Rank 5
Citrix NetScaler ADC / GatewayCVE-2026-3055
Citrix NetScaler Out-of-Bounds Read Vulnerability
CVSS severity 9.8critical
Added Mar 30, 2026
- Rank 6
Citrix NetScaler ADC / GatewayCVE-2025-7775
Citrix NetScaler Memory Overflow Vulnerability
CVSS severity 9.8critical
Added Aug 26, 2025
- Rank 7
Citrix NetScaler ADC / GatewayCVE-2025-6543
Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
CVSS severity 9.8critical
Added Jun 30, 2025
- Rank 8
Citrix ShareFileCVE-2023-24489
Citrix Content Collaboration ShareFile Improper Access Control Vulnerability
CVSS severity 9.8critical
Added Aug 16, 2023
- Rank 9
Citrix NetScaler ADC / GatewayCVE-2023-3519
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jul 19, 2023
- Rank 10
Citrix NetScaler ADC / GatewayCVE-2022-27518
Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability
CVSS severity 9.8critical
Added Dec 13, 2022
Show 16 more vulnerabilities
- Rank 11
Citrix SD-WANCVE-2017-6316
Citrix Multiple Products Remote Code Execution Vulnerability
CVE from 2017, added in 2022
CVSS severity 9.8critical
Added Mar 25, 2022
- Rank 12
Citrix SD-WANCVE-2019-12989
Citrix SD-WAN and NetScaler SQL Injection Vulnerability
CVE from 2019, added in 2022
CVSS severity 9.8critical
Added Mar 25, 2022
- Rank 13
Citrix ShareFileCVE-2021-22941
Citrix ShareFile Improper Access Control Vulnerability
Ransomware
CVSS severity 9.8critical
Added Mar 25, 2022
- Rank 14
Citrix Workspace app / ReceiverCVE-2019-11634
Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
RansomwareCVE from 2019, added in 2021
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 15
Citrix NetScaler ADC / GatewayCVE-2019-19781
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability
RansomwareCVE from 2019, added in 2021
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 16
Citrix NetScaler ADC / GatewayCVE-2023-6548
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
CVSS severity 8.8high
Added Jan 17, 2024
- Rank 17
Citrix SD-WANCVE-2019-12991
Citrix SD-WAN and NetScaler Command Injection Vulnerability
CVE from 2019, added in 2022
CVSS severity 8.8high
Added Mar 25, 2022
- Rank 18
Citrix Session RecordingCVE-2024-8068
Citrix Session Recording Improper Privilege Management Vulnerability
CVSS severity 8.0high
Added Aug 25, 2025
- Rank 19
Citrix Session RecordingCVE-2024-8069
Citrix Session Recording Deserialization of Untrusted Data Vulnerability
CVSS severity 8.0high
Added Aug 25, 2025
- Rank 20
Citrix NetScaler ADC / GatewayCVE-2025-5777
Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
Ransomware
CVSS severity 7.5high
Added Jul 10, 2025
- Rank 21
Citrix NetScaler ADC / GatewayCVE-2023-6549
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
CVSS severity 7.5high
Added Jan 17, 2024
- Rank 22
Citrix NetScaler ADC / GatewayCVE-2023-4966
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
Ransomware
CVSS severity 7.5high
Added Oct 18, 2023
- Rank 23
Citrix StoreFrontCVE-2019-13608
Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability
RansomwareCVE from 2019, added in 2021
CVSS severity 7.5high
Added Nov 3, 2021
- Rank 24
Citrix NetScaler ADC / GatewayCVE-2020-8193
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
CVSS severity 6.5medium
Added Nov 3, 2021
- Rank 25
Citrix NetScaler ADC / GatewayCVE-2020-8195
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
CVSS severity 6.5medium
Added Nov 3, 2021
- Rank 26
Citrix NetScaler ADC / GatewayCVE-2020-8196
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
CVSS severity 4.3medium
Added Nov 3, 2021
Follow and verify
Get new Citrix vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.