Citrix Systems, Inc.

First CVE: Mar 10, 2022Active for: 4 years
66
CVEs Published
More CVEs Published than 64% of tracked CNAs
13.2
Avg CVEs / Year
More Avg CVEs / Year than 60% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 64% of tracked CNAs
16.7%
In CISA KEV
Higher KEV Rate than 99% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Citrix Systems, Inc. as a CNA, 92.4% affect products that Citrix Systems, Inc. develops as a vendor.

92.4%
Self-reported: 61Third-party: 5

Of all the CVEs published that affect products developed by Citrix Systems, Inc., 13.3% are self-published by Citrix Systems, Inc. as a CNA.

13.3%
86.7%
Self-published: 61Published by other CNAs: 396

Trends Over Time

The number and severity of CVEs published by Citrix Systems, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2022
4 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Top CVEs

All CVEs published by Citrix Systems, Inc. as a CNA, regardless of affected vendor or product.

66 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unauthenticated remote code execution
Jul 19, 20239.899YESYES
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Jun 17, 20257.598YESYES
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.
Oct 10, 20237.598YESYES
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise t
Jul 10, 20239.897YESYES
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Rea
Jan 17, 20247.591YESYES
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual
Aug 26, 20259.883YESNO
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Pr
Jun 25, 20259.876YESNO
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway  in allows and attacker to perform cross site scripting
Jul 10, 20236.176NOYES
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the ses
Nov 12, 20248.074YESNO
  Cross-site scripting (XSS)
Jan 17, 20246.172NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA66 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local19 (28.8%)
Network41 (62.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network5 (7.6%)
Attack Complexity
Low63 (95.5%)
High3 (4.5%)
Unknown0 (0.0%)
User Interaction
None53 (80.3%)
Unknown0 (0.0%)
Required12 (18.2%)
Privileges Required
Low26 (39.4%)
High4 (6.1%)
None36 (54.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (66 CVEs).

CISA KEV
11 CVEs
16.7% of CVEs· 99th percentile
Metasploit
2 CVEs
3.0% of CVEs· 94th percentile
Nuclei
8 CVEs
12.1% of CVEs· 98th percentile
ExploitDB
1 CVE
1.5% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Citrix Systems, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Citrix Systems, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs