Brand
Citrix: actively exploited vulnerabilities
26 vulnerabilities in Citrix products (NetScaler ADC / Gateway, SD-WAN, Session Recording…) are in CISA’s catalog of exploited vulnerabilities, 4 of them added in the last 90 days. Last added: September 27, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
5 vulnerabilities added in the last 12 months
-
26 exploited vulnerabilities in the catalog, in total
-
3 added in the last 30 days
By category
Add just one Citrix category to your radar, or open its page.
- Load balancers and access gateways (ADC) 17 vulnerabilities
- Virtualization, VDI and cloud 4 vulnerabilities
- Switches, routers and SD-WAN 3 vulnerabilities
- Managed file transfer (MFT) 2 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- NetScaler ADC / Gateway 17 vulnerabilities · ADCs
- SD-WAN 3 vulnerabilities · Switches and routers
- Session Recording 2 vulnerabilities · Virtualization and VDI
- ShareFile 2 vulnerabilities · File transfer (MFT)
- StoreFront 1 vulnerability · Virtualization and VDI
- Workspace app / Receiver 1 vulnerability · Virtualization and VDI
Name used by CISA: Citrix. Product families: indicative classification by this site.
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 4, 2025 to Oct 3, 2025 | 0 |
| Oct 4, 2025 to Nov 2, 2025 | 0 |
| Nov 3, 2025 to Dec 2, 2025 | 0 |
| Dec 3, 2025 to Jan 1, 2026 | 0 |
| Jan 2, 2026 to Jan 31, 2026 | 0 |
| Feb 1, 2026 to Mar 2, 2026 | 0 |
| Mar 3, 2026 to Apr 1, 2026 | 1 |
| Apr 2, 2026 to May 1, 2026 | 0 |
| May 2, 2026 to May 31, 2026 | 0 |
| Jun 1, 2026 to Jun 30, 2026 | 0 |
| Jul 1, 2026 to Jul 30, 2026 | 0 |
| Jul 31, 2026 to Aug 29, 2026 | 1 |
| Aug 30, 2026 to Sep 28, 2026 (in progress) | 3 |
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Citrix list.
Rank 1Citrix NetScaler ADC / Gateway
CVE-2026-88771Recently addedActive CERT-FR alertHunt for compromise (CISA)
Citrix NetScaler Improper Input Validation Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 27, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 2Citrix NetScaler ADC / Gateway
CVE-2026-88772Recently addedActive CERT-FR alertHunt for compromise (CISA)
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 27, 2026
- CISA deadline
- 3 days
- CVSS severity
- 8.1 (high)
Rank 3Citrix NetScaler ADC / Gateway
CVE-2026-19490Recently addedHunt for compromise (CISA)
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 9, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 4Citrix NetScaler ADC / Gateway
CVE-2026-8452Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 26, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 5Citrix NetScaler ADC / Gateway
CVE-2026-3055Citrix NetScaler Out-of-Bounds Read Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Mar 30, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 6Citrix NetScaler ADC / Gateway
CVE-2025-7775Citrix NetScaler Memory Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 26, 2025
- CISA deadline
- 2 days
- CVSS severity
- 9.8 (critical)
Rank 7Citrix NetScaler ADC / Gateway
CVE-2025-6543Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 30, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 8Citrix ShareFile
CVE-2023-24489Citrix Content Collaboration ShareFile Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 16, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 9Citrix NetScaler ADC / Gateway
CVE-2023-3519Ransomware
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 19, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 10Citrix NetScaler ADC / Gateway
CVE-2022-27518Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 13, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Show 16 more vulnerabilities
Rank 11Citrix SD-WAN
CVE-2017-6316CVE from 2017, added in 2022
Citrix Multiple Products Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 12Citrix SD-WAN
CVE-2019-12989CVE from 2019, added in 2022
Citrix SD-WAN and NetScaler SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 13Citrix ShareFile
CVE-2021-22941Ransomware
Citrix ShareFile Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 14Citrix Workspace app / Receiver
CVE-2019-11634RansomwareCVE from 2019, added in 2021
Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 15Citrix NetScaler ADC / Gateway
CVE-2019-19781RansomwareCVE from 2019, added in 2021
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 16Citrix NetScaler ADC / Gateway
CVE-2023-6548Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 17, 2024
- CISA deadline
- 7 days
- CVSS severity
- 8.8 (high)
Rank 17Citrix SD-WAN
CVE-2019-12991CVE from 2019, added in 2022
Citrix SD-WAN and NetScaler Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 18Citrix Session Recording
CVE-2024-8068Citrix Session Recording Improper Privilege Management Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 25, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.0 (high)
Rank 19Citrix Session Recording
CVE-2024-8069Citrix Session Recording Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 25, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.0 (high)
Rank 20Citrix NetScaler ADC / Gateway
CVE-2025-5777Ransomware
Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 10, 2025
- CISA deadline
- 1 day
- CVSS severity
- 7.5 (high)
Rank 21Citrix NetScaler ADC / Gateway
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 17, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 22Citrix NetScaler ADC / Gateway
CVE-2023-4966Ransomware
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 18, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 23Citrix StoreFront
CVE-2019-13608RansomwareCVE from 2019, added in 2021
Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 24Citrix NetScaler ADC / Gateway
CVE-2020-8193Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 6.5 (medium)
Rank 25Citrix NetScaler ADC / Gateway
CVE-2020-8195Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 6.5 (medium)
Rank 26Citrix NetScaler ADC / Gateway
CVE-2020-8196Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 4.3 (medium)
Follow and verify
Get new Citrix vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.