Citrix Systems, Inc.
First CVE: Mar 10, 2022Active for: 4 years
66
CVEs Published
More CVEs Published than 64% of tracked CNAs
13.2
Avg CVEs / Year
More Avg CVEs / Year than 60% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 64% of tracked CNAs
16.7%
In CISA KEV
Higher KEV Rate than 99% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Citrix Systems, Inc. as a CNA, 92.4% affect products that Citrix Systems, Inc. develops as a vendor.
92.4%
Self-reported: 61Third-party: 5
Of all the CVEs published that affect products developed by Citrix Systems, Inc., 13.3% are self-published by Citrix Systems, Inc. as a CNA.
13.3%
86.7%
Self-published: 61Published by other CNAs: 396
Trends Over Time
The number and severity of CVEs published by Citrix Systems, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2022
4 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
Top CVEs
All CVEs published by Citrix Systems, Inc. as a CNA, regardless of affected vendor or product.
66 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-3519CRITICAL Unauthenticated remote code execution | Jul 19, 2023 | 9.8 | 99 | YES | YES |
CVE-2025-5777HIGH Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | Jun 17, 2025 | 7.5 | 98 | YES | YES |
CVE-2023-4966HIGH Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | Oct 10, 2023 | 7.5 | 98 | YES | YES |
CVE-2023-24489CRITICAL A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise t | Jul 10, 2023 | 9.8 | 97 | YES | YES |
CVE-2023-6549HIGH Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Rea | Jan 17, 2024 | 7.5 | 91 | YES | YES |
CVE-2025-7775CRITICAL Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual | Aug 26, 2025 | 9.8 | 83 | YES | NO |
CVE-2025-6543CRITICAL Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Pr | Jun 25, 2025 | 9.8 | 76 | YES | NO |
CVE-2023-24488MEDIUM Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting | Jul 10, 2023 | 6.1 | 76 | NO | YES |
CVE-2024-8069HIGH Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the ses | Nov 12, 2024 | 8.0 | 74 | YES | NO |
CVE-2023-5914MEDIUM Cross-site scripting (XSS) | Jan 17, 2024 | 6.1 | 72 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA66 CVEs
32%
53%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local19 (28.8%)
Network41 (62.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network5 (7.6%)
Attack Complexity
Low63 (95.5%)
High3 (4.5%)
Unknown0 (0.0%)
User Interaction
None53 (80.3%)
Unknown0 (0.0%)
Required12 (18.2%)
Privileges Required
Low26 (39.4%)
High4 (6.1%)
None36 (54.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (66 CVEs).
CISA KEV
11 CVEs
16.7% of CVEs· 99th percentile
Metasploit
2 CVEs
3.0% of CVEs· 94th percentile
Nuclei
8 CVEs
12.1% of CVEs· 98th percentile
ExploitDB
1 CVE
1.5% of CVEs· 85th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Citrix Systems, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Citrix Systems, Inc. as a CNA — matched by CVE ID, not by organization name.