Vendor

Citrix

As of , 27 Citrix vulnerabilities are on CISA's list of exploited vulnerabilities, 7 of them used in ransomware campaigns; 6 were added in 2026. Patch first: CVE-2026-19490.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-19490Authentication Bypass Using an Alternate Path or ChannelCitrix NetScalerPatch nowForensic triage required by CISA0.23
2CVE-2026-88772Improper Restriction of Operations within the Bounds of a Memory BufferCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
3CVE-2026-88771Improper Input ValidationCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
4CVE-2026-88779Improper Restriction of Operations within the Bounds of a Memory BufferCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
5CVE-2023-4966Buffer OverflowCitrix NetScaler ADC and NetScaler GatewayPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
6CVE-2023-3519Code InjectionCitrix NetScaler ADC and NetScaler GatewayPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
7CVE-2019-19781ADC, Gateway, and SD-WAN WANOP Appliance Code ExecutionCitrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP AppliancePatch this weekRansomware use; Metasploit module; EPSS 0.990.99
8CVE-2026-3055Out-of-Bounds ReadCitrix NetScalerPatch this weekMetasploit module0.04
9CVE-2019-12989SQL InjectionCitrix SD-WAN and NetScalerPatch this weekEPSS 0.95; verified Exploit-DB entry0.95
10CVE-2019-12991Command InjectionCitrix SD-WAN and NetScalerPatch this weekEPSS 0.74; verified Exploit-DB entry0.74
11CVE-2025-5777Out-of-Bounds ReadCitrix NetScaler ADC and GatewayPatch this weekRansomware use; EPSS 0.990.99
12CVE-2023-6549Buffer OverflowCitrix NetScaler ADC and NetScaler GatewayPatch this weekEPSS 0.580.58
13CVE-2023-24489ShareFile Improper Access ControlCitrix Content CollaborationPatch this weekEPSS 0.970.97
14CVE-2017-6316Multiple Products Remote Code ExecutionCitrix NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile ServerPatch this weekEPSS 0.730.73
15CVE-2020-8193ADC, Gateway, and SD-WAN WANOP Appliance Authorization BypassCitrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP AppliancePatch this weekEPSS 0.880.88
16CVE-2021-22941Improper Access ControlCitrix ShareFilePatch this weekRansomware use; EPSS 0.540.54
17CVE-2019-13608XML External Entity (XXE) ProcessingCitrix StoreFront ServerPatch this weekRansomware use0.30
18CVE-2019-11634Remote Code ExecutionCitrix Workspace Application and Receiver for WindowsPatch this weekRansomware use0.08
19CVE-2020-8195ADC, Gateway, and SD-WAN WANOP Appliance Information DisclosureCitrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP AppliancePatch soon0.33
20CVE-2025-7775Memory OverflowCitrix NetScalerPatch soon0.20
21CVE-2020-8196ADC, Gateway, and SD-WAN WANOP Appliance Information DisclosureCitrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP AppliancePatch soon0.26
22CVE-2024-8069Deserialization of Untrusted DataCitrix Session RecordingPatch soon0.15
23CVE-2025-6543Buffer OverflowCitrix NetScaler ADC and GatewayPatch soon0.11
24CVE-2022-27518Authentication BypassCitrix Application Delivery Controller (ADC) and GatewayPatch soon0.07
25CVE-2024-8068Improper Privilege ManagementCitrix Session RecordingPatch soon0.03

The next 2, from number 26

Products

Added each year

2462021: 6620212022: 5520222023: 3320232024: 2220242025: 5520252026: 662026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20216
20225
20233
20242
20255
20266

Used in ransomware

Changes CISA made to these entries

  1. CVE-2025-5777 Citrix NetScaler ADC and GatewayRansomware use: Unknown to Known.

Every change we recorded