Exploited CVEs / By vendor / Citrix

Citrix vulnerabilities actively exploited

22 Citrix CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2026-3055 (NetScaler, added 2026-03-30). 7 of the 22 are used in ransomware campaigns. New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

22 exploited CVEs7 ransomware-linked
Senserva AI Opinion and rich prompt for Citrix exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

NetScaler ADC and NetScaler Gateway: 4 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2023-6548NetScaler ADC and NetScaler Gateway2024-01-17CVSS 8.8, EPSS 3%
CVE-2023-6549NetScaler ADC and NetScaler Gateway2024-01-17CVSS 7.5, EPSS 58%
CVE-2023-4966NetScaler ADC and NetScaler Gateway2023-10-18ransomware, CVSS 7.5, EPSS 100%
CVE-2023-3519NetScaler ADC and NetScaler Gateway2023-07-19ransomware, CVSS 9.8, EPSS 100%

Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance: 4 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2019-19781Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance2021-11-03ransomware, CVSS 9.8, EPSS 100%
CVE-2020-8193Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance2021-11-03CVSS 6.5, EPSS 88%
CVE-2020-8195Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance2021-11-03CVSS 6.5, EPSS 33%
CVE-2020-8196Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance2021-11-03CVSS 4.3, EPSS 26%

Other Citrix products

CVEProductAdded to KEVSignals
CVE-2026-3055NetScaler2026-03-30CVSS 9.8, EPSS 84%
CVE-2025-7775NetScaler2025-08-26CVSS 9.8, EPSS 20%
CVE-2024-8068Session Recording2025-08-25CVSS 8.0, EPSS 1%
CVE-2024-8069Session Recording2025-08-25CVSS 8.0, EPSS 15%
CVE-2025-5777NetScaler ADC and Gateway2025-07-10ransomware, CVSS 7.5, EPSS 100%
CVE-2025-6543NetScaler ADC and Gateway2025-06-30CVSS 9.8, EPSS 10%
CVE-2023-24489Content Collaboration2023-08-16CVSS 9.8, EPSS 95%
CVE-2022-27518Application Delivery Controller (ADC) and Gateway2022-12-13CVSS 9.8, EPSS 7%
CVE-2017-6316NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server2022-03-25CVSS 9.8, EPSS 73%
CVE-2019-12989SD-WAN and NetScaler2022-03-25CVSS 9.8, EPSS 94%
CVE-2019-12991SD-WAN and NetScaler2022-03-25CVSS 8.8, EPSS 74%
CVE-2021-22941ShareFile2022-03-25ransomware, CVSS 9.8, EPSS 54%
CVE-2019-11634Workspace Application and Receiver for Windows2021-11-03ransomware, CVSS 9.8, EPSS 8%
CVE-2019-13608StoreFront Server2021-11-03ransomware, CVSS 7.5, EPSS 30%

Common questions about exploited Citrix CVEs

Which Citrix vulnerabilities are actively exploited?

As of August 2026, 22 Citrix CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are NetScaler ADC and NetScaler Gateway (4), Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance (4). 7 are linked to ransomware campaigns.

What is the newest exploited Citrix CVE?

CVE-2026-3055, affecting NetScaler, added to the CISA KEV catalog on 2026-03-30. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these Citrix CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited Citrix CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest Citrix KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.