Vendor Exploitation Record

Citrix (NetScaler ADC and NetScaler Gateway) — Known Exploited Vulnerabilities

23 in CISA KEV · 7 ransomware-linked · as of 2026-08-31
In CISA KEV23 confirmed exploited
Ransomware-linked7 (30% of KEV, per CISA)
First KEV addition2021-11-03
Most recent2026-08-26

How we count

Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Citrix (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.

Exploited Citrix vulnerabilities (CISA KEV)

CVEProductVulnerabilityAdded
CVE-2026-8452NetScaler ADC and NetScaler GatewayCitrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability2026-08-26
CVE-2026-3055NetScalerCitrix NetScaler Out-of-Bounds Read Vulnerability2026-03-30
CVE-2025-7775NetScalerCitrix NetScaler Memory Overflow Vulnerability2025-08-26
CVE-2024-8068Session RecordingCitrix Session Recording Improper Privilege Management Vulnerability2025-08-25
CVE-2024-8069Session RecordingCitrix Session Recording Deserialization of Untrusted Data Vulnerability2025-08-25
CVE-2025-5777NetScaler ADC and GatewayCitrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability2025-07-10ransomware
CVE-2025-6543NetScaler ADC and GatewayCitrix NetScaler ADC and Gateway Buffer Overflow Vulnerability2025-06-30
CVE-2023-6549NetScaler ADC and NetScaler GatewayCitrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability2024-01-17
CVE-2023-6548NetScaler ADC and NetScaler GatewayCitrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability2024-01-17
CVE-2023-4966NetScaler ADC and NetScaler GatewayCitrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability2023-10-18ransomware
CVE-2023-24489Content CollaborationCitrix Content Collaboration ShareFile Improper Access Control Vulnerability2023-08-16
CVE-2023-3519NetScaler ADC and NetScaler GatewayCitrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability2023-07-19ransomware
CVE-2022-27518Application Delivery Controller (ADC) and GatewayCitrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability2022-12-13
CVE-2021-22941ShareFileCitrix ShareFile Improper Access Control Vulnerability2022-03-25ransomware
CVE-2019-12991SD-WAN and NetScalerCitrix SD-WAN and NetScaler Command Injection Vulnerability2022-03-25
CVE-2019-12989SD-WAN and NetScalerCitrix SD-WAN and NetScaler SQL Injection Vulnerability2022-03-25
CVE-2017-6316NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile ServerCitrix Multiple Products Remote Code Execution Vulnerability2022-03-25
CVE-2019-13608StoreFront ServerCitrix StoreFront Server XML External Entity (XXE) Processing Vulnerability2021-11-03ransomware
CVE-2020-8193Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceCitrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability2021-11-03
CVE-2020-8195Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceCitrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability2021-11-03
CVE-2020-8196Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceCitrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability2021-11-03
CVE-2019-19781Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceCitrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability2021-11-03ransomware
CVE-2019-11634Workspace Application and Receiver for WindowsCitrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability2021-11-03ransomware

← All vendors by exploited-vulnerability count

🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.

Track newly exploited vulnerabilities

Free daily briefing on CVEs added to CISA KEV and exploited in the wild.