Citrix Systems operates a broadly represented portfolio of virtualization, application delivery, and remote-access infrastructure products that sit in business-critical and internet-facing positions across enterprise environments. Vulnerabilities affecting the vendor skew toward serious outcomes: a meaningful share reach critical severity, frequently acquire public exploit code, and have a moderate tendency toward confirmed in-the-wild exploitation and CISA catalog inclusion. The exposure concentrates in flagship products such as NetScaler Gateway, NetScaler Application Delivery Controller, and its hypervisor platforms, and recurs through weakness classes including cross-site scripting, improper input validation, and memory-buffer handling issues that are characteristic of complex network and management software. Defenders should prioritize inventory and patching of internet-exposed NetScaler appliances and treat this vendor's security advisories as high-impact across their deployment footprint; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Citrix Systems, Inc. over time
Of all the CVEs published by Citrix Systems, Inc. as a CNA, 92.4% affect products that Citrix Systems, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Citrix Systems, Inc., 13.3% are self-published by Citrix Systems, Inc. as a CNA.
Signals from CVEs in this vendor scope (457 CVEs).
457 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-3519CRITICAL Unauthenticated remote code execution | Jul 19, 2023 | 9.8 | 99 | YES | YES |
CVE-2019-19781CRITICAL An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal. | Dec 27, 2019 | 9.8 | 99 | YES | YES |
CVE-2014-6271CRITICAL GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra | Sep 24, 2014 | 9.8 | 99 | YES | YES |
CVE-2026-3055CRITICAL Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread | Mar 23, 2026 | 9.8 | 98 | YES | YES |
CVE-2025-5777HIGH Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | Jun 17, 2025 | 7.5 | 98 | YES | YES |
CVE-2023-4966HIGH Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | Oct 10, 2023 | 7.5 | 98 | YES | YES |
CVE-2019-12989CRITICAL Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. | Jul 16, 2019 | 9.8 | 98 | YES | YES |
CVE-2014-7169CRITICAL GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri | Sep 25, 2014 | 9.8 | 98 | YES | YES |
CVE-2023-24489CRITICAL A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise t | Jul 10, 2023 | 9.8 | 97 | YES | YES |
CVE-2020-8193MEDIUM Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1. | Jul 10, 2020 | 6.5 | 95 | YES | YES |
Signals from CVEs in this vendor scope (457 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Citrix Systems, Inc..
Media articles that mention a CVE ID that affects a product developed by Citrix Systems, Inc. — matched by CVE ID, not by vendor name.