citrix has 7 CVEs on record between 2019 and 2026. 2 were published in the last 90 days. The median CVSS is 9.8 (critical), with 5 rated critical. 86% have been exploited in the wild — well above the 1% corpus average, so citrix flaws are worth patching on sight. The median gap from publication to a KEV listing is 22 days (6 cases). Most affected products: netscaler_application_delivery_controller (4), Citrix Workspace app for Windows (1), application_delivery_controller_firmware (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 86% vs 1% corpus
- Median CVSS
- 9.8
- Publish → KEV
- 22 d median(6)
- Last 90 days
- 2 prev 0
Products
- netscaler_application_delivery_controller 4
- Citrix Workspace app for Windows 1
- application_delivery_controller_firmware 1
- receiver 1
Worst active — by depth score
CVE-2023-4966Critical· 9.4Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.100CVE-2023-3519Critical· 9.8Unauthenticated remote code execution100CVE-2019-19781Critical· 9.8An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0100CVE-2025-5777High· 7.5Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server91CVE-2019-11634Critical· 9.8Citrix Workspace App before 1904 for Windows has Incorrect Access Control.86
citrix vulnerabilities
CVEs affecting citrix, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-78547Medium· 4.4Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.
Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.
CVE-2026-19490Critical· 9.8CISA KEVPoCVulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
CVE-2025-5777High· 7.5CISA KEVPoCInsufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CVE-2023-4966Critical· 9.4CISA KEVPoCSensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
CVE-2023-3519Critical· 9.8CISA KEV0dayPoCUnauthenticated remote code execution
Unauthenticated remote code execution
CVE-2019-19781Critical· 9.8CISA KEVPoCAn issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
CVE-2019-11634Critical· 9.8CISA KEVCitrix Workspace App before 1904 for Windows has Incorrect Access Control.
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.