Citrix Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Citrix products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

24

In CISA KEV

16

Beyond CISA KEV

8

Sensor Observed

3

Virtual Patch Available

0

Citrix KEVs Added by Year

Loading...

24 Citrix KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2020-8982

An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the...

High Not in CISA 27 Dec 2025
CVE-2019-12990

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.

High Not in CISA 13 Jun 2025
CVE-2019-12987

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).

High Not in CISA 13 Jun 2025
CVE-2019-12986

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).

High Not in CISA 13 Jun 2025
CVE-2019-12985

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).

High Not in CISA 13 Jun 2025
CVE-2020-8191

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix...

High Not in CISA 14 Jun 2025
CVE-2020-8209

Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before...

High Not in CISA 14 Jun 2025
CVE-2024-8069

Limited remote code execution with privilege of a NetworkService Account access

Confirmed In CISA 01 Jun 2026
CVE-2024-8068

Privilege escalation to NetworkService Account access

Confirmed In CISA 01 Jun 2026
CVE-2023-24488

Cross site scripting

High Not in CISA 28 Apr 2025
CVE-2019-11634

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

Confirmed In CISA 03 Nov 2021
CVE-2019-19781

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

Confirmed In CISA 03 Nov 2021
CVE-2020-8196

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix...

Confirmed In CISA 03 Nov 2021
CVE-2020-8195

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix...

Confirmed In CISA 03 Nov 2021
CVE-2020-8193

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix...

Confirmed In CISA 03 Nov 2021
CVE-2019-13608

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

Confirmed In CISA 03 Nov 2021
CVE-2017-6316

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie....

Confirmed In CISA 25 Mar 2022
CVE-2019-12989

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.

Confirmed In CISA 25 Mar 2022
CVE-2019-12991

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

Confirmed In CISA 25 Mar 2022
CVE-2021-22941

Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise...

Confirmed In CISA 25 Mar 2022
CVE-2022-27518

Unauthenticated remote arbitrary code execution

Confirmed In CISA 13 Dec 2022
CVE-2023-3519

Unauthenticated remote code execution

Confirmed In CISA 19 Jul 2023
CVE-2023-24489

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated...

Confirmed In CISA 16 Aug 2023
CVE-2023-4966

Unauthenticated sensitive information disclosure

Confirmed In CISA 18 Oct 2023

Common Vulnerability Classes (CWE)

  • CWE-284 — Improper Access Control 5
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
  • CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 2
  • CWE-611 — Improper Restriction of XML External Entity Reference 1
  • CWE-664 — Improper Control of a Resource Through its Lifetime 1
  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology