Citrix
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Citrix product.
RSS Feeds for Citrix security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Citrix products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Citrix Sorted by Most Security Vulnerabilities since 2018
Known Exploited Citrix Vulnerabilities
The following Citrix vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
Title | Description | Added |
---|---|---|
Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability |
Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server. CVE-2025-5777 Exploit Probability: 16.6% |
July 10, 2025 |
Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability |
Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server. CVE-2025-6543 Exploit Probability: 16.1% |
June 30, 2025 |
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability |
Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP. CVE-2023-6548 Exploit Probability: 23.4% |
January 17, 2024 |
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability |
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. CVE-2023-6549 Exploit Probability: 14.7% |
January 17, 2024 |
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability |
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. CVE-2023-4966 Exploit Probability: 94.4% |
October 18, 2023 |
Citrix Content Collaboration ShareFile Improper Access Control Vulnerability |
Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers. CVE-2023-24489 Exploit Probability: 94.2% |
August 16, 2023 |
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability |
Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution. CVE-2023-3519 Exploit Probability: 92.7% |
July 19, 2023 |
Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability |
Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability which allows an attacker to execute code as administrator. CVE-2022-27518 Exploit Probability: 9.8% |
December 13, 2022 |
Citrix Multiple Products Remote Code Execution Vulnerability |
A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server. CVE-2017-6316 Exploit Probability: 88.4% |
March 25, 2022 |
Citrix SD-WAN and NetScaler SQL Injection Vulnerability |
Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection. CVE-2019-12989 Exploit Probability: 80.8% |
March 25, 2022 |
Citrix SD-WAN and NetScaler Command Injection Vulnerability |
Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance. CVE-2019-12991 Exploit Probability: 85.9% |
March 25, 2022 |
Citrix ShareFile Improper Access Control Vulnerability |
Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller. CVE-2021-22941 Exploit Probability: 88.6% |
March 25, 2022 |
Citrix StoreFront Server Multiple Versions XML External Entity (XXE) |
Citrix StoreFront Server contains a XXE processing vulnerability that could allow an unauthenticated attacker to retrieve potentially sensitive information. CVE-2019-13608 Exploit Probability: 29.4% |
November 3, 2021 |
Citrix Workspace (for Windows) Prior to 1904 Improper Access Control |
Citrix Workspace app and Receiver for Windows prior to version 1904 contains an incorrect access control vulnerability which allows for code execution. CVE-2019-11634 Exploit Probability: 59.6% |
November 3, 2021 |
Citrix Application Delivery Controller and Citrix Gateway Vulnerability |
Issue in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0 allowing Directory Traversal. CVE-2019-19781 Exploit Probability: 94.4% |
November 3, 2021 |
Citrix ADC, Citrix Gateway, Citrix SDWAN WANOP Unauthenticated Authorization Bypass |
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users. CVE-2020-8196 Exploit Probability: 63.9% |
November 3, 2021 |
Citrix ADC, Citrix Gateway, Citrix SDWAN WANOP Unauthenticated Authorization Bypass |
Application Delivery Controller (ADC), Gateway, and SDWAN WANOP CVE-2020-8195 Exploit Probability: 85.3% |
November 3, 2021 |
Citrix ADC, Citrix Gateway, Citrix SDWAN WANOP Unauthenticated Authorization Bypass |
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints. CVE-2020-8193 Exploit Probability: 94.3% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 10 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 4 known exploited Citrix vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
By the Year
In 2025 there have been 2 vulnerabilities in Citrix with an average score of 8.7 out of ten. Last year, in 2024 Citrix had 9 security vulnerabilities published. Right now, Citrix is on track to have less security vulnerabilities in 2025 than it did last year. However, the average CVE base score of the vulnerabilities in 2025 is greater by 0.96.
Year | Vulnerabilities | Average Score |
---|---|---|
2025 | 2 | 8.65 |
2024 | 9 | 7.69 |
2023 | 15 | 7.15 |
2022 | 15 | 7.21 |
2021 | 13 | 7.72 |
2020 | 25 | 7.56 |
2019 | 18 | 8.92 |
2018 | 30 | 7.76 |
It may take a day or so for new Citrix vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Citrix Security Vulnerabilities
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server
CVE-2025-6543
9.8 - Critical
- June 25, 2025
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server
CVE-2025-5777
7.5 - High
- June 17, 2025
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Use of Uninitialized Resource
Local privilege escalation
CVE-2024-7889
7.3 - High
- September 11, 2024
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
Local privilege escalation
CVE-2024-7890
7.3 - High
- September 11, 2024
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
Denial of Service in NetScaler Console (formerly NetScaler ADM)
CVE-2024-6236
7.5 - High
- July 10, 2024
Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX
Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5
CVE-2024-6148
8.8 - High
- July 10, 2024
Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5
Sensitive information disclosure in NetScaler Console
CVE-2024-6235
8.8 - High
- July 10, 2024
Sensitive information disclosure in NetScaler Console
An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may
CVE-2024-5661
6 - Medium
- June 13, 2024
An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive.
Cross SiteScripting vulnerability in Citrix Session Recording
CVE-2023-6184
7.2 - High
- January 18, 2024
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
XSS
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway
CVE-2023-6549
7.5 - High
- January 17, 2024
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
Buffer Overflow
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway
CVE-2023-6548
8.8 - High
- January 17, 2024
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
Code Injection
Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server
CVE-2023-4967
7.5 - High
- October 27, 2023
Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server
Buffer Overflow
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server
CVE-2023-4966
7.5 - High
- October 10, 2023
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA ?virtual?server.
Privilege Escalation to root administrator (nsroot)
CVE-2023-3467
8 - High
- July 19, 2023
Privilege Escalation to root administrator (nsroot)
Reflected Cross-Site Scripting (XSS)
CVE-2023-3466
6.1 - Medium
- July 19, 2023
Reflected Cross-Site Scripting (XSS)
XSS
Unauthenticated remote code execution
CVE-2023-3519
9.8 - Critical
- July 19, 2023
Unauthenticated remote code execution
Code Injection
Users with only access to launch VDA applications
CVE-2023-24490
4.3 - Medium
- July 10, 2023
Users with only access to launch VDA applications can launch an unauthorized desktop
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could
CVE-2023-24489
9.8 - Critical
- July 10, 2023
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway? in
CVE-2023-24488
6.1 - Medium
- July 10, 2023
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway? in allows and attacker to perform cross site scripting
XSS
Arbitrary file read in Citrix ADC and Citrix Gateway?
CVE-2023-24487
7.5 - High
- July 10, 2023
Arbitrary file read in Citrix ADC and Citrix Gateway?
A vulnerability has been identified in Citrix Workspace app for Linux
CVE-2023-24486
5.5 - Medium
- July 10, 2023
A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched.
A vulnerability has been identified
CVE-2023-24483
7.8 - High
- February 16, 2023
A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.
Improper Privilege Management
A malicious user can cause log files to be written to a directory
CVE-2023-24484
5.5 - Medium
- February 16, 2023
A malicious user can cause log files to be written to a directory that they do not have permission to write to.
Vulnerabilities have been identified
CVE-2023-24485
7.8 - High
- February 16, 2023
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
AuthZ
Authenticated denial of service
CVE-2022-27507
6.5 - Medium
- January 26, 2023
Authenticated denial of service
Resource Exhaustion
Unauthenticated denial of service
CVE-2022-27508
7.5 - High
- January 26, 2023
Unauthenticated denial of service
Resource Exhaustion
In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint
CVE-2019-18177
6.5 - Medium
- December 26, 2022
In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.
User login brute force protection functionality bypass
CVE-2022-27516
9.8 - Critical
- November 08, 2022
User login brute force protection functionality bypass
Improper Restriction of Excessive Authentication Attempts
Unauthorized access to Gateway user capabilities
CVE-2022-27510
9.8 - Critical
- November 08, 2022
Unauthorized access to Gateway user capabilities
authentification
Remote desktop takeover
CVE-2022-27513
9.6 - Critical
- November 08, 2022
Remote desktop takeover via phishing
Insufficient Verification of Data Authenticity
Unauthenticated redirection to a malicious website
CVE-2022-27509
6.1 - Medium
- July 28, 2022
Unauthenticated redirection to a malicious website
Open Redirect
Temporary disruption of the ADM license service
CVE-2022-27512
5.3 - Medium
- June 16, 2022
Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM.
Dangling pointer
Corruption of the system by a remote, unauthenticated user
CVE-2022-27511
8.1 - High
- June 16, 2022
Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has rebooted.
An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could
CVE-2022-21827
7.1 - High
- May 26, 2022
An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM.
Improper Privilege Management
In Citrix XenMobile Server through 10.12 RP9
CVE-2021-44519
8.8 - High
- April 19, 2022
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.
Directory traversal
Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9
CVE-2022-27503
6.1 - Medium
- April 13, 2022
Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9
XSS
Hard-coded credentials
CVE-2022-27506
2.7 - Low
- April 13, 2022
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
Use of Hard-coded Credentials
Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4
CVE-2022-26151
7.2 - High
- April 13, 2022
Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
Command Injection
In Citrix XenMobile Server through 10.12 RP9
CVE-2021-44520
8.8 - High
- April 13, 2022
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.
Command Injection
Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments
CVE-2022-26355
4.4 - Medium
- March 10, 2022
Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if PowerShell was used when configuring FAS to store the registration authority certificates private key in the TPM. It does not occur if the TPM was not selected for use or if the FAS administration console was used for configuration.
Exposure of Resource to Wrong Sphere
An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed
CVE-2022-21825
7.8 - High
- February 09, 2022
An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation.
An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23
CVE-2021-22956
7.5 - High
- December 07, 2021
An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
Resource Exhaustion
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could
CVE-2021-22955
7.5 - High
- December 07, 2021
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
Resource Exhaustion
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may
CVE-2021-22941
9.8 - Critical
- September 23, 2021
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.
An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller
CVE-2021-22932
7.5 - High
- August 16, 2021
An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file encryption option to become disabled if it had previously been enabled. Customers are only affected by this issue if they previously selected Enable Encryption in the ShareFile configuration page and did not re-select this setting after running the CTX269106 mitigation tool. ShareFile customers who have not run the CTX269106 mitigation tool or who re-selected Enable Encryption immediately after running the tool are unaffected by this issue.
Missing Encryption of Sensitive Data
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway)
CVE-2021-22920
6.5 - Medium
- August 05, 2021
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to a phishing attack through a SAML authentication hijack to steal a valid user session.
A vulnerability has been identified in Citrix Virtual Apps and Desktops
CVE-2021-22928
7.8 - High
- August 05, 2021
A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on that Windows VDA to SYSTEM.
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway)
CVE-2021-22919
7.5 - High
- August 05, 2021
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the appliances being fully consumed.
Allocation of Resources Without Limits or Throttling
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider
CVE-2021-22927
8.1 - High
- August 05, 2021
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
Session Fixation
Citrix Cloud Connector before 6.31.0.62192 suffers
CVE-2021-22914
7.5 - High
- June 16, 2021
Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files. Such information could be used by an malicious actor to access a Citrix Cloud environment. This issue affects all versions of Citrix Cloud Connector that were installed by passing secure client parameters for installation via the command line. The issue does not affect Citrix Cloud Connector if it was installed using the interactive installer or where a parameter file was used with the command-line installer.
Insecure Storage of Sensitive Information