IT
58.465 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync

Citrix vulnerabilities

402 CVE

Citrix vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2026-88772 HIGH 8.1 citrix netscaler_application_delivery_controller Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote 1.3%
CVE-2026-88771 CRIT 9.8 citrix netscaler_application_delivery_controller Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13 1.1%
CVE-2026-19490 CRIT 9.8 citrix netscaler_application_delivery_controller Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. 7.0%
CVE-2026-8452 CRIT 9.8 citrix netscaler_application_delivery_controller Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server 1.0%
CVE-2026-3055 CRIT 9.8 citrix netscaler_application_delivery_controller Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread 4.0%
CVE-2025-7775 CRIT 9.8 citrix netscaler_application_delivery_controller Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC a 19.6%
CVE-2024-8069 HIGH 8.0 citrix session_recording Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server 14.6%
CVE-2024-8068 HIGH 8.0 citrix session_recording Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain 3.5%
CVE-2025-5777 HIGH 7.5 ransomware citrix netscaler_application_delivery_controller Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server 100.0%
CVE-2025-6543 CRIT 9.8 citrix netscaler_application_delivery_controller Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server 10.6%
CVE-2023-6549 HIGH 8.2 citrix netscaler_application_delivery_controller Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read 57.6%
CVE-2023-6548 MED 5.5 citrix netscaler_application_delivery_controller Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interf 3.2%
CVE-2023-4966 CRIT 9.4 ransomware citrix netscaler_application_delivery_controller Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server. 100.0%
CVE-2023-24489 CRIT 9.8 citrix sharefile_storage_zones_controller A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller. 97.3%
CVE-2023-3519 CRIT 9.8 ransomware citrix netscaler_application_delivery_controller Unauthenticated remote code execution 99.7%
CVE-2022-27518 CRIT 9.8 citrix application_delivery_controller_firmware Unauthenticated remote arbitrary code execution 6.7%
CVE-2021-22941 CRIT 9.8 ransomware citrix sharefile_storagezones_controller Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller. 53.6%
CVE-2019-12991 HIGH 8.8 citrix netscaler_sd-wan Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). 74.1%
CVE-2019-12989 CRIT 9.8 citrix netscaler_sd-wan Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. 95.0%
CVE-2017-6316 CRIT 9.8 citrix netscaler_sd-wan Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID. 73.0%
CVE-2014-7169 CRIT 9.8 apple mac_os_x GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as 99.9%
CVE-2014-6271 CRIT 9.8 apple mac_os_x GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature 100.0%
CVE-2020-8196 MED 4.3 citrix application_delivery_controller_firmware Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privil 26.3%
CVE-2020-8195 MED 6.5 citrix application_delivery_controller_firmware Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low priv 33.0%
CVE-2020-8193 MED 6.5 citrix application_delivery_controller_firmware Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints. 88.4%