How we count
Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Citrix (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.
Exploited Citrix vulnerabilities (CISA KEV)
| CVE | Product | Vulnerability | Added | |
|---|---|---|---|---|
| CVE-2026-8452 | NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | 2026-08-26 | |
| CVE-2026-3055 | NetScaler | Citrix NetScaler Out-of-Bounds Read Vulnerability | 2026-03-30 | |
| CVE-2025-7775 | NetScaler | Citrix NetScaler Memory Overflow Vulnerability | 2025-08-26 | |
| CVE-2024-8068 | Session Recording | Citrix Session Recording Improper Privilege Management Vulnerability | 2025-08-25 | |
| CVE-2024-8069 | Session Recording | Citrix Session Recording Deserialization of Untrusted Data Vulnerability | 2025-08-25 | |
| CVE-2025-5777 | NetScaler ADC and Gateway | Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability | 2025-07-10 | ransomware |
| CVE-2025-6543 | NetScaler ADC and Gateway | Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability | 2025-06-30 | |
| CVE-2023-6549 | NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | 2024-01-17 | |
| CVE-2023-6548 | NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | 2024-01-17 | |
| CVE-2023-4966 | NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | 2023-10-18 | ransomware |
| CVE-2023-24489 | Content Collaboration | Citrix Content Collaboration ShareFile Improper Access Control Vulnerability | 2023-08-16 | |
| CVE-2023-3519 | NetScaler ADC and NetScaler Gateway | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | 2023-07-19 | ransomware |
| CVE-2022-27518 | Application Delivery Controller (ADC) and Gateway | Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability | 2022-12-13 | |
| CVE-2021-22941 | ShareFile | Citrix ShareFile Improper Access Control Vulnerability | 2022-03-25 | ransomware |
| CVE-2019-12991 | SD-WAN and NetScaler | Citrix SD-WAN and NetScaler Command Injection Vulnerability | 2022-03-25 | |
| CVE-2019-12989 | SD-WAN and NetScaler | Citrix SD-WAN and NetScaler SQL Injection Vulnerability | 2022-03-25 | |
| CVE-2017-6316 | NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server | Citrix Multiple Products Remote Code Execution Vulnerability | 2022-03-25 | |
| CVE-2019-13608 | StoreFront Server | Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability | 2021-11-03 | ransomware |
| CVE-2020-8193 | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability | 2021-11-03 | |
| CVE-2020-8195 | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability | 2021-11-03 | |
| CVE-2020-8196 | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability | 2021-11-03 | |
| CVE-2019-19781 | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability | 2021-11-03 | ransomware |
| CVE-2019-11634 | Workspace Application and Receiver for Windows | Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability | 2021-11-03 | ransomware |
← All vendors by exploited-vulnerability count
🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.