CyberMax
Home › Exploited CVEs

Citrix known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 24 Citrix CVEs as exploited in the wild. 3 were added in the last 12 months (latest 2026-09-09), and 7 are known to be used in ransomware campaigns.

Citrix CVEs added to CISA KEV per year
2021: 6202162022: 5202252023: 3202332024: 2202422025: 5202552026: 320263

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Citrix products

NetScaler ADC and NetScaler Gateway (5), Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance (4), NetScaler (3), Session Recording (2), NetScaler ADC and Gateway (2), SD-WAN and NetScaler (2), Content Collaboration (1), Application Delivery Controller (ADC) and Gateway (1), ShareFile (1), NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server (1), StoreFront Server (1), Workspace Application and Receiver for Windows (1).

All Citrix CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-19490NetScalerNetScaler Authentication Bypass Using an Alternate Path or Channel2026-09-092026-09-127.0%–
CVE-2026-8452NetScaler ADC and NetScaler GatewayNetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer2026-08-262026-08-291.0%–
CVE-2026-3055NetScalerNetScaler Out-of-Bounds Read2026-03-302026-04-024.0%–
CVE-2025-7775NetScalerNetScaler Memory Overflow2025-08-262025-08-2819.6%–
CVE-2024-8069Session RecordingSession Recording Deserialization of Untrusted Data2025-08-252025-09-1514.6%–
CVE-2024-8068Session RecordingSession Recording Improper Privilege Management2025-08-252025-09-153.5%–
CVE-2025-5777NetScaler ADC and GatewayNetScaler ADC and Gateway Out-of-Bounds Read2025-07-102025-07-11100.0%Yes
CVE-2025-6543NetScaler ADC and GatewayNetScaler ADC and Gateway Buffer Overflow2025-06-302025-07-2110.6%–
CVE-2023-6549NetScaler ADC and NetScaler GatewayNetScaler ADC and NetScaler Gateway Buffer Overflow2024-01-172024-02-0757.6%–
CVE-2023-6548NetScaler ADC and NetScaler GatewayNetScaler ADC and NetScaler Gateway Code Injection2024-01-172024-01-243.2%–
CVE-2023-4966NetScaler ADC and NetScaler GatewayNetScaler ADC and NetScaler Gateway Buffer Overflow2023-10-182023-11-08100.0%Yes
CVE-2023-24489Content CollaborationContent Collaboration ShareFile Improper Access Control2023-08-162023-09-0697.3%–
CVE-2023-3519NetScaler ADC and NetScaler GatewayNetScaler ADC and NetScaler Gateway Code Injection2023-07-192023-08-0999.7%Yes
CVE-2022-27518Application Delivery Controller (ADC) and GatewayApplication Delivery Controller (ADC) and Gateway Authentication Bypass2022-12-132023-01-036.7%–
CVE-2021-22941ShareFileShareFile Improper Access Control2022-03-252022-04-1553.6%Yes
CVE-2019-12991SD-WAN and NetScalerSD-WAN and NetScaler Command Injection2022-03-252022-04-1574.1%–
CVE-2019-12989SD-WAN and NetScalerSD-WAN and NetScaler SQL Injection2022-03-252022-04-1595.0%–
CVE-2017-6316NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile ServerMultiple Products Remote Code Execution2022-03-252022-04-1573.0%–
CVE-2020-8196Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure2021-11-032022-05-0326.3%–
CVE-2020-8195Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure2021-11-032022-05-0333.0%–
CVE-2020-8193Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass2021-11-032022-05-0388.4%–
CVE-2019-19781Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceADC, Gateway, and SD-WAN WANOP Appliance Code Execution2021-11-032022-05-03100.0%Yes
CVE-2019-13608StoreFront ServerStoreFront Server XML External Entity (XXE) Processing2021-11-032022-05-0330.0%Yes
CVE-2019-11634Workspace Application and Receiver for WindowsWorkspace Application and Receiver for Windows Remote Code Execution2021-11-032022-05-038.0%Yes
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors