Citrix security briefs
13 published alerts for Citrix products and services.
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Citrix NetScaler is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-19490). Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. CISA remediation due date: 2026-09-12. If you need help checking exposure, call (864) 335-9223.
NetScaler ADC and NetScaler Gateway vulnerability
Citrix NetScaler ADC and NetScaler Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-8452). Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service. CISA remediation due date: 2026-08-29. If you need help checking exposure, call (864) 335-9223.
Citrix NetScaler Out-of-Bounds Read Vulnerability
Citrix NetScaler is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-3055). Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread. CISA remediation due date: 2026-04-02. If you need help checking exposure, call (864) 335-9223.
Citrix NetScaler Memory Overflow Vulnerability
Citrix NetScaler is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-7775). Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service. CISA remediation due date: 2025-08-28. If you need help checking exposure, call (864) 335-9223.
Citrix Session Recording Deserialization of Untrusted Data Vulnerability
Citrix Session Recording is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-8069). Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server. CISA remediation due date: 2025-09-15. If you need help checking exposure, call (864) 335-9223.
Citrix Session Recording Improper Privilege Management Vulnerability
Citrix Session Recording is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-8068). Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain. CISA remediation due date: 2025-09-15. If you need help checking exposure, call (864) 335-9223.
Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
Citrix NetScaler ADC and Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-5777). Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server. CISA remediation due date: 2025-07-11. If you need help checking exposure, call (864) 335-9223.
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
Citrix NetScaler ADC and NetScaler Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-4966). Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. CISA remediation due date: 2023-11-08. If you need help checking exposure, call (864) 335-9223.
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Citrix NetScaler ADC and NetScaler Gateway is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-3519). Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution. CISA remediation due date: 2023-08-09. If you need help checking exposure, call (864) 335-9223.
Citrix ShareFile Improper Access Control Vulnerability
Citrix ShareFile is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-22941). Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller. CISA remediation due date: 2022-04-15. If you need help checking exposure, call (864) 335-9223.
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability
Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-19781). Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability
Citrix StoreFront Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-13608). Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
Citrix Workspace Application and Receiver for Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-11634). Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.