Citrix Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Citrix products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
24
In CISA KEV
16
Beyond CISA KEV
8
Sensor Observed
3
Virtual Patch Available
0
Citrix KEVs Added by Year
24 Citrix KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2020-8982
An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the... |
ShareFile StorageZones Controller | High | Not in CISA | 27 Dec 2025 |
|
CVE-2019-12990
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal. |
SD-WAN | High | Not in CISA | 13 Jun 2025 |
|
CVE-2019-12987
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6). |
SD-WAN | High | Not in CISA | 13 Jun 2025 |
|
CVE-2019-12986
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6). |
SD-WAN | High | Not in CISA | 13 Jun 2025 |
|
CVE-2019-12985
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6). |
SD-WAN | High | Not in CISA | 13 Jun 2025 |
|
CVE-2020-8191
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix... |
Citrix ADC and Citrix Gateway | High | Not in CISA | 14 Jun 2025 |
|
CVE-2020-8209
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before... |
XenMobile Server | High | Not in CISA | 14 Jun 2025 |
|
CVE-2024-8069
Limited remote code execution with privilege of a NetworkService Account access |
Citrix Session Recording | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2024-8068
Privilege escalation to NetworkService Account access |
Citrix Session Recording | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2023-24488
Cross site scripting |
Citrix ADC and Citrix Gateway | High | Not in CISA | 28 Apr 2025 |
|
CVE-2019-11634
Citrix Workspace App before 1904 for Windows has Incorrect Access Control. |
Workspace App | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-19781
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal. |
Application Delivery Controller and Gateway | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-8196
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix... |
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-8195
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix... |
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-8193
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix... |
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-13608
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks. |
StoreFront Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-6316
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie.... |
NetScaler SD-WAN | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2019-12989
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. |
SD-WAN | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2019-12991
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). |
SD-WAN | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2021-22941
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise... |
Citrix ShareFile storage zones controller | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2022-27518
Unauthenticated remote arbitrary code execution |
Citrix Gateway, Citrix ADC | Confirmed | In CISA | 13 Dec 2022 |
|
CVE-2023-3519
Unauthenticated remote code execution |
NetScaler ADC, NetScaler Gateway | Confirmed | In CISA | 19 Jul 2023 |
|
CVE-2023-24489
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated... |
Citrix ShareFile Storage Zones Controller | Confirmed | In CISA | 16 Aug 2023 |
|
CVE-2023-4966
Unauthenticated sensitive information disclosure |
NetScaler ADC, NetScaler Gateway | Confirmed | In CISA | 18 Oct 2023 |
Common Vulnerability Classes (CWE)
- CWE-284 — Improper Access Control 5
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
- CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 2
- CWE-611 — Improper Restriction of XML External Entity Reference 1
- CWE-664 — Improper Control of a Resource Through its Lifetime 1
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology