FAIL › dossier
Citrix
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 60%
Citrix is a major provider of network security and virtualization solutions, but its security track record is marred by a relentless stream of critical vulnerabilities, especially in its flagship NetScaler ADC and Gateway products. These flaws, including multiple RCEs and memory overflows, have been actively exploited by ransomware groups, forcing customers into a constant cycle of urgent patching.
Citrix has a poor security posture characterized by a high frequency of critical and high-severity vulnerabilities, particularly remote code execution (RCE) and memory overflow flaws in its core NetScaler ADC and Gateway products. Many of these vulnerabilities have been actively exploited in the wild, including by ransomware groups, and often require urgent patches.
- CVE-2023-3519: Unauthenticated RCE in NetScaler ADC/Gateway
- CVE-2025-5777: Out-of-bounds read exploited by ransomware
- CVE-2023-4966: Buffer overflow exploited by ransomware
- CVE-2026-8655: Memory overflow leading to DoS in NetScaler ADC
- CVE-2026-8452: Memory overflow leading to DoS in NetScaler ADC
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2019-19781 | critical | Citrix ADC, Gateway, and SD-WAN appliances had a critical, unauthenticated code execution vulnerability actively exploited in the wild, potentially allowing attackers to take control of systems. |
| 2026-08-26 | CVE-2026-8452 | high | An unauthenticated attacker can execute arbitrary code as root on Citrix NetScaler ADC and Gateway appliances via CVE-2026-8452. |
| 2025-07-10 | CVE-2025-5777 | critical | Citrix NetScaler ADC and Gateway suffered an out-of-bounds read vulnerability linked to ransomware that was actively exploited in the wild. |
| 2023-10-18 | CVE-2023-4966 | critical | Citrix NetScaler ADC and Gateway suffered a critical buffer overflow vulnerability that was actively exploited in the wild and linked to ransomware attacks. |
| 2023-07-19 | CVE-2023-3519 | critical | Citrix NetScaler ADC and Gateway suffered an unauthenticated remote code execution vulnerability that was actively exploited in the wild and linked to ransomware attacks. |
| 2022-03-25 | CVE-2017-6316 | high | Citrix NetScaler and XenMobile Server management interfaces allowed unauthenticated remote attackers to execute arbitrary code as root. |
| 2022-03-25 | CVE-2019-12991 | high | Citrix SD-WAN and NetScaler suffered an authenticated command injection flaw that allowed attackers to execute arbitrary commands on the devices. |
| 2021-11-03 | CVE-2020-8195 | high | Citrix ADC/Gateway/SD-WAN appliances suffer an information disclosure flaw actively exploited in the wild, exposing sensitive data and undermining trust in a vendor with a recent history of critical RCE 0-days. |
| 2021-11-03 | CVE-2020-8196 | high | Citrix ADC/Gateway/SD-WAN appliances suffer an information disclosure flaw actively exploited in the wild, exposing sensitive data and undermining trust in a vendor with a recent history of critical RCE 0-days. |
| 2022-03-25 | CVE-2019-12989 | high | Citrix SD-WAN and NetScaler suffered a SQL injection vulnerability that was actively exploited in the wild. |
| 2025-08-26 | CVE-2025-7775 | high | Citrix NetScaler exposed to remote code execution due to memory overflow |
| 2025-08-25 | CVE-2024-8068 | high | Citrix Session Recording exposed to unauthorized privilege escalation due to improper access controls. |
| 2025-08-25 | CVE-2024-8069 | high | Citrix Session Recording exposed RCE due to untrusted data deserialization, exploited in the wild by unauthenticated attackers on the same intranet |
| 2025-06-30 | CVE-2025-6543 | high | Citrix NetScaler ADC and Gateway suffered a buffer overflow that led to unintended control flow and Denial of Service, actively exploited in the wild. |
| 2022-12-13 | CVE-2022-27518 | high | Citrix ADC & Gateway AD auth bypass exploited |
| 2022-03-25 | CVE-2021-22941 | critical | Citrix ShareFile allowed unauthenticated attackers to remotely compromise storage zones controllers, actively exploited and linked to ransomware activity. |
| 2021-11-03 | CVE-2019-13608 | critical | Citrix StoreFront Server had an unauthenticated XXE vulnerability actively exploited by ransomware actors, allowing data retrieval. |
| 2021-11-03 | CVE-2019-11634 | critical | Citrix Workspace software had a remote code execution vulnerability actively exploited by ransomware actors, allowing attackers to execute arbitrary code on affected systems. |
| 2024-01-17 | CVE-2023-6548 | high | Citrix NetScaler ADC/Gateway allows authenticated remote code execution on management interfaces via CVE-2023-6548, actively exploited in the wild. |
| 2021-11-03 | CVE-2020-8193 | high | Citrix ADC/Gateway/SD-WAN appliances suffer an authorization bypass allowing unauthenticated access to specific URL endpoints if the attacker has the NetScaler IP. |
| 2023-08-16 | CVE-2023-24489 | high | Citrix ShareFile allowed unauthenticated attackers to remotely compromise customer storage zones due to improper access controls, and is currently being exploited in the wild. |
| 2026-03-30 | CVE-2026-3055 | high | Citrix NetScaler SAML IDP configuration allows out-of-bounds memory reads, enabling attackers to read sensitive data without code execution. |
| 2024-01-17 | CVE-2023-6549 | high | Citrix NetScaler ADC/Gateway buffer overflow vulnerability (CVE-2023-6549) allows denial-of-service in VPN/AAA configurations and is actively exploited in the wild. |
| 2026-06-30 | CVE-2026-8655 | critical | Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured |
| 2026-06-30 | CVE-2026-8452 | critical | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server |
| 2023-07-19 | CVE-2023-3519 | critical | CVE-2023-3519: Unauthenticated remote code execution |
| 2019-12-27 | CVE-2019-19781 | critical | CVE-2019-19781: An issue was discovered in Citrix Application Delivery Controller (ADC) and Gate |
| 2019-05-22 | CVE-2019-11634 | critical | CVE-2019-11634: Citrix Workspace App before 1904 for Windows has Incorrect Access Control. |
"An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal."
"Citrix Workspace App before 1904 for Windows has Incorrect Access Control."
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Citrix for Government | Authorized | Moderate |
- Citrix — Funding, Team & Competitive Intelligence | CybersecRadars · cybersecradars.com
- Cisco - Wikipedia · en.wikipedia.org
- CITRIX | Support · support.citrix.com
- Nvd - Cve-2026-53565 · NVD
- Security Bulletins for XenServer - Citrix Customer Support · support.citrix.com
- Citrix Systems - Overview, News & Similar companies - ZoomInfo · www.zoominfo.com
- Broadcom - Overview, News & Similar companies | ZoomInfo.com · www.zoominfo.com
- Federal Workforce Data (FWD) · data.opm.gov