Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

Citrix

Citrix NetScaler ADC and Gateway vulnerabilities, including session-hijacking flaws like Citrix Bleed that bypass MFA entirely.

22 CVEs1 articlesRSS
CVEs
CVE-2026-3055
[ CRITICAL ]CVSS 9.8EPSS 84.5%kev

Citrix NetScaler Out-of-Bounds Read Vulnerability

Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.

Citrix / NetScaler
CVE-2025-7775
[ CRITICAL ]CVSS 9.8EPSS 19.6%kev

Citrix NetScaler Memory Overflow Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.

Citrix / NetScaler
CVE-2024-8068
[ HIGH ]CVSS 8.0EPSS 1.4%kev

Citrix Session Recording Improper Privilege Management Vulnerability

Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain.

Citrix / Session Recording
CVE-2024-8069
[ HIGH ]CVSS 8.0EPSS 14.7%kev

Citrix Session Recording Deserialization of Untrusted Data Vulnerability

Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server.

Citrix / Session Recording
CVE-2025-6543
[ CRITICAL ]CVSS 9.8EPSS 10.1%kev

Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability

Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.

Citrix / NetScaler ADC and Gateway
CVE-2025-5777
[ HIGH ]CVSS 7.5EPSS 100.0%kev

Citrix Bleed 2 — NetScaler ADC/Gateway memory-disclosure leaking session tokens

Unauthenticated memory-overread in NetScaler ADC and NetScaler Gateway leaking live session tokens past MFA. On CISA KEV; Anubis-affiliate exploitation observed.

Citrix / NetScaler ADC and NetScaler Gateway
CVE-2023-6548
[ MEDIUM ]CVSS 5.5EPSS 3.2%kev

Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.

Citrix / NetScaler ADC and NetScaler Gateway
CVE-2023-6549
[ HIGH ]CVSS 8.2EPSS 57.6%kev

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

Citrix / NetScaler ADC and NetScaler Gateway
CVE-2023-4966
[ CRITICAL ]CVSS 9.4EPSS 100.0%kev

Citrix Bleed — NetScaler ADC and Gateway Sensitive Information Disclosure

A buffer-overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway allows attackers to harvest valid session tokens from device memory, hijacking authenticated sessions and bypassing MFA entirely. Widely known as "Citrix Bleed."

Citrix / NetScaler ADC and NetScaler Gateway
CVE-2023-24489
[ CRITICAL ]CVSS 9.8EPSS 94.7%kev

Citrix Content Collaboration ShareFile Improper Access Control Vulnerability

Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers.

Citrix / Content Collaboration
CVE-2023-3519
[ CRITICAL ]CVSS 9.8EPSS 99.7%kev

Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.

Citrix / NetScaler ADC and NetScaler Gateway
CVE-2022-27518
[ CRITICAL ]CVSS 9.8EPSS 6.9%kev

Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.

Citrix / Application Delivery Controller (ADC) and Gateway
CVE-2017-6316
[ CRITICAL ]CVSS 9.8EPSS 72.6%kev

Citrix Multiple Products Remote Code Execution Vulnerability

A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.

Citrix / NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server
CVE-2019-12989
[ CRITICAL ]CVSS 9.8EPSS 94.1%kev

Citrix SD-WAN and NetScaler SQL Injection Vulnerability

Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.

Citrix / SD-WAN and NetScaler
CVE-2019-12991
[ HIGH ]CVSS 8.8EPSS 74.1%kev

Citrix SD-WAN and NetScaler Command Injection Vulnerability

Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.

Citrix / SD-WAN and NetScaler
CVE-2021-22941
[ CRITICAL ]CVSS 9.8EPSS 53.6%kev

Citrix ShareFile Improper Access Control Vulnerability

Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.

Citrix / ShareFile
CVE-2019-11634
[ CRITICAL ]CVSS 9.8EPSS 8.0%kev

Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability

Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.

Citrix / Workspace Application and Receiver for Windows
CVE-2019-13608
[ HIGH ]CVSS 7.5EPSS 30.0%kev

Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability

Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.

Citrix / StoreFront Server
CVE-2019-19781
[ CRITICAL ]CVSS 9.8EPSS 100.0%kev

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.

Citrix / Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
CVE-2020-8193
[ MEDIUM ]CVSS 6.5EPSS 88.4%kev

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.

Citrix / Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
CVE-2020-8195
[ MEDIUM ]CVSS 6.5EPSS 33.3%kev

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

Citrix / Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
CVE-2020-8196
[ MEDIUM ]CVSS 4.3EPSS 26.3%kev

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

Citrix / Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
Articles