Citrix vendor intelligence

Citrix Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Citrix products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse Citrix KEVs Full KEV feed
Total KEVs
24
Known exploited vulnerabilities affecting Citrix products
In CISA KEV
16
Records also listed in the official catalog
Beyond CISA KEV
8
Additional exploited CVEs absent from CISA KEV
Sensor Observed
5
Citrix KEVs with sensor-observed exploitation activity

The catalog gap matters for Citrix exposure

Eight of the 24 exploited Citrix CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss one-third of this vendor portfolio.

67%
Covered by CISA
33%
Beyond CISA
15
Product families

Attested Citrix CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2020-8982

An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the...

ShareFile StorageZones Controller High Beyond CISA 27 Dec 2025
CVE-2019-12990

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.

SD-WAN High Beyond CISA 13 Jun 2025
CVE-2019-12987

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).

SD-WAN High Beyond CISA 13 Jun 2025
CVE-2019-12986

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).

SD-WAN Confirmed Beyond CISA 13 Jun 2025
CVE-2019-12985

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).

SD-WAN Confirmed Beyond CISA 13 Jun 2025
CVE-2020-8191

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix...

Citrix ADC and Citrix Gateway High Beyond CISA 14 Jun 2025
CVE-2020-8209

Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before...

XenMobile Server High Beyond CISA 14 Jun 2025
CVE-2024-8069

Limited remote code execution with privilege of a NetworkService Account access

Citrix Session Recording Confirmed In CISA 01 Jun 2026
CVE-2024-8068

Privilege escalation to NetworkService Account access

Citrix Session Recording Confirmed In CISA 01 Jun 2026
CVE-2023-24488

Cross site scripting

Citrix ADC and Citrix Gateway  High Beyond CISA 28 Apr 2025
CVE-2019-11634

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

Workspace App Confirmed In CISA 03 Nov 2021
CVE-2019-19781

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

Application Delivery Controller and Gateway Confirmed In CISA 03 Nov 2021
CVE-2020-8196

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix...

Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP Confirmed In CISA 03 Nov 2021
CVE-2020-8195

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix...

Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP Confirmed In CISA 03 Nov 2021
CVE-2020-8193

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix...

Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP Confirmed In CISA 03 Nov 2021
CVE-2019-13608

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

StoreFront Server Confirmed In CISA 03 Nov 2021
CVE-2017-6316

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie....

NetScaler SD-WAN Confirmed In CISA 25 Mar 2022
CVE-2019-12989

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.

SD-WAN Confirmed In CISA 25 Mar 2022
CVE-2019-12991

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

SD-WAN Confirmed In CISA 25 Mar 2022
CVE-2021-22941

Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise...

Citrix ShareFile storage zones controller Confirmed In CISA 25 Mar 2022
CVE-2022-27518

Unauthenticated remote arbitrary code execution

Citrix Gateway, Citrix ADC Confirmed In CISA 13 Dec 2022
CVE-2023-3519

Unauthenticated remote code execution

NetScaler ADC, NetScaler Gateway Confirmed In CISA 19 Jul 2023
CVE-2023-24489

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated...

Citrix ShareFile Storage Zones Controller Confirmed In CISA 16 Aug 2023
CVE-2023-4966

Unauthenticated sensitive information disclosure

NetScaler ADC, NetScaler Gateway Confirmed In CISA 18 Oct 2023

Showing 24 of 24 Citrix known exploited vulnerabilities.

Recurring weakness patterns

Access control, neutralization, and limitation account for thirteen mapped occurrences across this Citrix KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.