Skip to content
COOEY

FAIL › dossier

Citrix

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 60%

Citrix is a major provider of network security and virtualization solutions, but its security track record is marred by a relentless stream of critical vulnerabilities, especially in its flagship NetScaler ADC and Gateway products. These flaws, including multiple RCEs and memory overflows, have been actively exploited by ransomware groups, forcing customers into a constant cycle of urgent patching.

PROFILE
CategoryNetwork Security & VirtualizationWhat they doCitrix provides app and desktop virtualization for secure remote access to resources.HQFort Lauderdale, United StatesOwnershipprivate Websitehttps://www.citrix.com ↗
SECURITY POSTURE

Citrix has a poor security posture characterized by a high frequency of critical and high-severity vulnerabilities, particularly remote code execution (RCE) and memory overflow flaws in its core NetScaler ADC and Gateway products. Many of these vulnerabilities have been actively exploited in the wild, including by ransomware groups, and often require urgent patches.

Notable failures
  • CVE-2023-3519: Unauthenticated RCE in NetScaler ADC/Gateway
  • CVE-2025-5777: Out-of-bounds read exploited by ransomware
  • CVE-2023-4966: Buffer overflow exploited by ransomware
  • CVE-2026-8655: Memory overflow leading to DoS in NetScaler ADC
  • CVE-2026-8452: Memory overflow leading to DoS in NetScaler ADC
Patterns: Repeated critical RCE and memory overflow vulnerabilities in NetScaler ADC/Gateway; Active exploitation of vulnerabilities in the wild by ransomware actors; Frequent unpatched edge-device RCEs and buffer overflows
FAILURE HISTORY · 28
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2019-19781 critical Citrix ADC, Gateway, and SD-WAN appliances had a critical, unauthenticated code execution vulnerability actively exploited in the wild, potentially allowing attackers to take control of systems.
2026-08-26 CVE-2026-8452 high An unauthenticated attacker can execute arbitrary code as root on Citrix NetScaler ADC and Gateway appliances via CVE-2026-8452.
2025-07-10 CVE-2025-5777 critical Citrix NetScaler ADC and Gateway suffered an out-of-bounds read vulnerability linked to ransomware that was actively exploited in the wild.
2023-10-18 CVE-2023-4966 critical Citrix NetScaler ADC and Gateway suffered a critical buffer overflow vulnerability that was actively exploited in the wild and linked to ransomware attacks.
2023-07-19 CVE-2023-3519 critical Citrix NetScaler ADC and Gateway suffered an unauthenticated remote code execution vulnerability that was actively exploited in the wild and linked to ransomware attacks.
2022-03-25 CVE-2017-6316 high Citrix NetScaler and XenMobile Server management interfaces allowed unauthenticated remote attackers to execute arbitrary code as root.
2022-03-25 CVE-2019-12991 high Citrix SD-WAN and NetScaler suffered an authenticated command injection flaw that allowed attackers to execute arbitrary commands on the devices.
2021-11-03 CVE-2020-8195 high Citrix ADC/Gateway/SD-WAN appliances suffer an information disclosure flaw actively exploited in the wild, exposing sensitive data and undermining trust in a vendor with a recent history of critical RCE 0-days.
2021-11-03 CVE-2020-8196 high Citrix ADC/Gateway/SD-WAN appliances suffer an information disclosure flaw actively exploited in the wild, exposing sensitive data and undermining trust in a vendor with a recent history of critical RCE 0-days.
2022-03-25 CVE-2019-12989 high Citrix SD-WAN and NetScaler suffered a SQL injection vulnerability that was actively exploited in the wild.
2025-08-26 CVE-2025-7775 high Citrix NetScaler exposed to remote code execution due to memory overflow
2025-08-25 CVE-2024-8068 high Citrix Session Recording exposed to unauthorized privilege escalation due to improper access controls.
2025-08-25 CVE-2024-8069 high Citrix Session Recording exposed RCE due to untrusted data deserialization, exploited in the wild by unauthenticated attackers on the same intranet
2025-06-30 CVE-2025-6543 high Citrix NetScaler ADC and Gateway suffered a buffer overflow that led to unintended control flow and Denial of Service, actively exploited in the wild.
2022-12-13 CVE-2022-27518 high Citrix ADC & Gateway AD auth bypass exploited
2022-03-25 CVE-2021-22941 critical Citrix ShareFile allowed unauthenticated attackers to remotely compromise storage zones controllers, actively exploited and linked to ransomware activity.
2021-11-03 CVE-2019-13608 critical Citrix StoreFront Server had an unauthenticated XXE vulnerability actively exploited by ransomware actors, allowing data retrieval.
2021-11-03 CVE-2019-11634 critical Citrix Workspace software had a remote code execution vulnerability actively exploited by ransomware actors, allowing attackers to execute arbitrary code on affected systems.
2024-01-17 CVE-2023-6548 high Citrix NetScaler ADC/Gateway allows authenticated remote code execution on management interfaces via CVE-2023-6548, actively exploited in the wild.
2021-11-03 CVE-2020-8193 high Citrix ADC/Gateway/SD-WAN appliances suffer an authorization bypass allowing unauthenticated access to specific URL endpoints if the attacker has the NetScaler IP.
2023-08-16 CVE-2023-24489 high Citrix ShareFile allowed unauthenticated attackers to remotely compromise customer storage zones due to improper access controls, and is currently being exploited in the wild.
2026-03-30 CVE-2026-3055 high Citrix NetScaler SAML IDP configuration allows out-of-bounds memory reads, enabling attackers to read sensitive data without code execution.
2024-01-17 CVE-2023-6549 high Citrix NetScaler ADC/Gateway buffer overflow vulnerability (CVE-2023-6549) allows denial-of-service in VPN/AAA configurations and is actively exploited in the wild.
2026-06-30 CVE-2026-8655 critical Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured
2026-06-30 CVE-2026-8452 critical Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
2023-07-19 CVE-2023-3519 critical CVE-2023-3519: Unauthenticated remote code execution
2019-12-27 CVE-2019-19781 critical CVE-2019-19781: An issue was discovered in Citrix Application Delivery Controller (ADC) and Gate
2019-05-22 CVE-2019-11634 critical CVE-2019-11634: Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.70
synthesissevere-fallout-0.60
synthesissevere-fallout-0.70
synthesisnegative-0.70
synthesissevere-fallout-0.70
synthesissevere-fallout-0.60
synthesisneutral+0.00
No sentiment expressed; purely factual NVD entry.
synthesissevere-fallout-0.60
CVE-2019-11634 was a critical access control flaw in Citrix Workspace App, leading to potential unauthorized access and data breaches, resulting in significant reputational and financial fallout for C
cooey ↗severe-fallout-0.70
"…"
cooey ↗severe-fallout-1.00
negative
"…"
cooey ↗severe-fallout-0.70
"…"
cooey ↗severe-fallout-0.70
"…"
cooey ↗severe-fallout-0.70
"…"
cooey ↗negative-0.70
"…"
cooey ↗neutral+0.00
No sentiment expressed; purely factual NVD entry.
"An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal."
cooey ↗severe-fallout-0.60
Critical access control flaw in Citrix Workspace App, leading to potential unauthorized access and data breaches, resulting in significant reputational and financial fallout for Citrix.
"Citrix Workspace App before 1904 for Windows has Incorrect Access Control."
FEDRAMP CATALOG PRODUCTS · 1
PRODUCTSTATUSIMPACT
Citrix for GovernmentAuthorizedModerate
Open questions: Exact current employee count · Specific financial impact of CVE-2023-3519 and subsequent exploits
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-16 04:44:37.770819+00:00