Citrix known exploited vulnerabilities
CISA lists 24 Citrix CVEs as exploited in the wild. 3 were added in the last 12 months (latest 2026-09-09), and 7 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2023-4966 (NetScaler ADC and NetScaler Gateway): EPSS 100.0%, added 2023-10-18
- CVE-2019-19781 (Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance): EPSS 100.0%, added 2021-11-03
- CVE-2025-5777 (NetScaler ADC and Gateway): EPSS 100.0%, added 2025-07-10
- CVE-2023-3519 (NetScaler ADC and NetScaler Gateway): EPSS 99.7%, added 2023-07-19
- CVE-2023-24489 (Content Collaboration): EPSS 97.3%, added 2023-08-16
Most affected Citrix products
NetScaler ADC and NetScaler Gateway (5), Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance (4), NetScaler (3), Session Recording (2), NetScaler ADC and Gateway (2), SD-WAN and NetScaler (2), Content Collaboration (1), Application Delivery Controller (ADC) and Gateway (1), ShareFile (1), NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server (1), StoreFront Server (1), Workspace Application and Receiver for Windows (1).
All Citrix CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-19490 | NetScaler | NetScaler Authentication Bypass Using an Alternate Path or Channel | 2026-09-09 | 2026-09-12 | 7.0% | – |
| CVE-2026-8452 | NetScaler ADC and NetScaler Gateway | NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer | 2026-08-26 | 2026-08-29 | 1.0% | – |
| CVE-2026-3055 | NetScaler | NetScaler Out-of-Bounds Read | 2026-03-30 | 2026-04-02 | 4.0% | – |
| CVE-2025-7775 | NetScaler | NetScaler Memory Overflow | 2025-08-26 | 2025-08-28 | 19.6% | – |
| CVE-2024-8069 | Session Recording | Session Recording Deserialization of Untrusted Data | 2025-08-25 | 2025-09-15 | 14.6% | – |
| CVE-2024-8068 | Session Recording | Session Recording Improper Privilege Management | 2025-08-25 | 2025-09-15 | 3.5% | – |
| CVE-2025-5777 | NetScaler ADC and Gateway | NetScaler ADC and Gateway Out-of-Bounds Read | 2025-07-10 | 2025-07-11 | 100.0% | Yes |
| CVE-2025-6543 | NetScaler ADC and Gateway | NetScaler ADC and Gateway Buffer Overflow | 2025-06-30 | 2025-07-21 | 10.6% | – |
| CVE-2023-6549 | NetScaler ADC and NetScaler Gateway | NetScaler ADC and NetScaler Gateway Buffer Overflow | 2024-01-17 | 2024-02-07 | 57.6% | – |
| CVE-2023-6548 | NetScaler ADC and NetScaler Gateway | NetScaler ADC and NetScaler Gateway Code Injection | 2024-01-17 | 2024-01-24 | 3.2% | – |
| CVE-2023-4966 | NetScaler ADC and NetScaler Gateway | NetScaler ADC and NetScaler Gateway Buffer Overflow | 2023-10-18 | 2023-11-08 | 100.0% | Yes |
| CVE-2023-24489 | Content Collaboration | Content Collaboration ShareFile Improper Access Control | 2023-08-16 | 2023-09-06 | 97.3% | – |
| CVE-2023-3519 | NetScaler ADC and NetScaler Gateway | NetScaler ADC and NetScaler Gateway Code Injection | 2023-07-19 | 2023-08-09 | 99.7% | Yes |
| CVE-2022-27518 | Application Delivery Controller (ADC) and Gateway | Application Delivery Controller (ADC) and Gateway Authentication Bypass | 2022-12-13 | 2023-01-03 | 6.7% | – |
| CVE-2021-22941 | ShareFile | ShareFile Improper Access Control | 2022-03-25 | 2022-04-15 | 53.6% | Yes |
| CVE-2019-12991 | SD-WAN and NetScaler | SD-WAN and NetScaler Command Injection | 2022-03-25 | 2022-04-15 | 74.1% | – |
| CVE-2019-12989 | SD-WAN and NetScaler | SD-WAN and NetScaler SQL Injection | 2022-03-25 | 2022-04-15 | 95.0% | – |
| CVE-2017-6316 | NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server | Multiple Products Remote Code Execution | 2022-03-25 | 2022-04-15 | 73.0% | – |
| CVE-2020-8196 | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure | 2021-11-03 | 2022-05-03 | 26.3% | – |
| CVE-2020-8195 | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure | 2021-11-03 | 2022-05-03 | 33.0% | – |
| CVE-2020-8193 | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass | 2021-11-03 | 2022-05-03 | 88.4% | – |
| CVE-2019-19781 | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | ADC, Gateway, and SD-WAN WANOP Appliance Code Execution | 2021-11-03 | 2022-05-03 | 100.0% | Yes |
| CVE-2019-13608 | StoreFront Server | StoreFront Server XML External Entity (XXE) Processing | 2021-11-03 | 2022-05-03 | 30.0% | Yes |
| CVE-2019-11634 | Workspace Application and Receiver for Windows | Workspace Application and Receiver for Windows Remote Code Execution | 2021-11-03 | 2022-05-03 | 8.0% | Yes |
Read next: Which CVEs to patch first this week · All vendors