Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Citrix Systems, Inc.

First CVE: Mar 29, 2000Active for: 26 yearsTotal CVEs: 457
68.3
VTI Score
TOP TARGET

Citrix Systems operates a broadly represented portfolio of virtualization, application delivery, and remote-access infrastructure products that sit in business-critical and internet-facing positions across enterprise environments. Vulnerabilities affecting the vendor skew toward serious outcomes: a meaningful share reach critical severity, frequently acquire public exploit code, and have a moderate tendency toward confirmed in-the-wild exploitation and CISA catalog inclusion. The exposure concentrates in flagship products such as NetScaler Gateway, NetScaler Application Delivery Controller, and its hypervisor platforms, and recurs through weakness classes including cross-site scripting, improper input validation, and memory-buffer handling issues that are characteristic of complex network and management software. Defenders should prioritize inventory and patching of internet-exposed NetScaler appliances and treat this vendor's security advisories as high-impact across their deployment footprint; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
457
Total CVEs
More Total CVEs than 100% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
5.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Citrix Systems, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 29, 2000
26 years ago
Most Recent CVE
Jun 30, 2026
25 days ago

Self-Reporting Analysis

Of all the CVEs published by Citrix Systems, Inc. as a CNA, 92.4% affect products that Citrix Systems, Inc. develops as a vendor.

92.4%
Self-reported: 61 (92.4%)
Third-party: 5 (7.6%)

Of all the CVEs published that affect products developed by Citrix Systems, Inc., 13.3% are self-published by Citrix Systems, Inc. as a CNA.

13.3%
86.7%
Self-published: 61 (13.3%)
Other CNAs: 396 (86.7%)

Products(153 total)

Top CVEs

Signals from CVEs in this vendor scope (457 CVEs).

457 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-3519CRITICAL
Unauthenticated remote code execution
Jul 19, 20239.899YESYES
CVE-2019-19781CRITICAL
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
Dec 27, 20199.899YESYES
CVE-2014-6271CRITICAL
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra
Sep 24, 20149.899YESYES
CVE-2026-3055CRITICAL
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
Mar 23, 20269.898YESYES
CVE-2025-5777HIGH
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Jun 17, 20257.598YESYES
CVE-2023-4966HIGH
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.
Oct 10, 20237.598YESYES
CVE-2019-12989CRITICAL
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
Jul 16, 20199.898YESYES
CVE-2014-7169CRITICAL
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri
Sep 25, 20149.898YESYES
CVE-2023-24489CRITICAL
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise t
Jul 10, 20239.897YESYES
CVE-2020-8193MEDIUM
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.
Jul 10, 20206.595YESYES
View all 457 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products457 CVEs
37%
48%
11%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local117 (25.6%)
Network183 (40.0%)
Unknown147 (32.2%)
Physical2 (0.4%)
Adjacent Network8 (1.8%)
Attack Complexity
Low284 (62.1%)
High26 (5.7%)
Unknown147 (32.2%)
User Interaction
None274 (60.0%)
Unknown147 (32.2%)
Required36 (7.9%)
Privileges Required
Low143 (31.3%)
High15 (3.3%)
None152 (33.3%)
Unknown147 (32.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (457 CVEs).

CISA KEV
24 CVEs
5.3% of CVEs· 99th percentile
Metasploit
11 CVEs
2.4% of CVEs· 97th percentile
Nuclei
22 CVEs
4.8% of CVEs· 96th percentile
ExploitDB
32 CVEs
7.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Citrix Systems, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Citrix Systems, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Citrix Systems, Inc.'s Products

View all 12 CNAs →

Top CWEs