Skip to content

Data collected

CVEs Live

Citrix vulnerabilities exploited in the wild

The Citrix CVEs that CISA lists as exploited, newest first. Only confirmed exploitation appears here, each with its EPSS and the CVSS as published.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

26
flaws with confirmed attacks
7
used by ransomware
1.5%
of the whole catalog

12 vulnerabilities · newest first.Showing the entries bundled with this page while the full catalog loads.

RSS of KEV additions
  1. CVE-2026-88772Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · NetScaler

    Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Severity

    9.5CRITICALCVSS 4.0 · 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5

    Attack probability (EPSS)

    1.30%69th pct

    KEV dates

    added due
  2. CVE-2026-88771Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · NetScaler

    Citrix NetScaler Improper Input Validation Vulnerability

    Severity

    9.5CRITICALCVSS 4.0 · 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5

    Attack probability (EPSS)

    1.06%63th pct

    KEV dates

    added due
  3. CVE-2026-19490Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · NetScaler

    Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Severity

    9.3CRITICALCVSS 4.0 · 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5

    Attack probability (EPSS)

    23.2%98th pct

    KEV dates

    added due
  4. CVE-2026-8452Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · NetScaler ADC and NetScaler Gateway

    Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Severity

    8.8HIGHCVSS 4.0 · 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5

    Attack probability (EPSS)

    1.01%62th pct

    KEV dates

    added due
  5. CVE-2026-3055Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · NetScaler

    Citrix NetScaler Out-of-Bounds Read Vulnerability

    Severity

    9.3CRITICALCVSS 4.0 · 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5

    Attack probability (EPSS)

    4.04%90th pct

    KEV dates

    added due
  6. CVE-2025-7775Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · NetScaler

    Citrix NetScaler Memory Overflow Vulnerability

    Severity

    9.2CRITICALCVSS 4.0 · citrix.com

    Attack probability (EPSS)

    19.6%97th pct

    KEV dates

    added due
  7. CVE-2024-8069Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · Session Recording

    Citrix Session Recording Deserialization of Untrusted Data Vulnerability

    Severity

    5.1MEDIUMCVSS 4.0 · citrix.com

    Attack probability (EPSS)

    14.6%97th pct

    KEV dates

    added due
  8. CVE-2024-8068Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · Session Recording

    Citrix Session Recording Improper Privilege Management Vulnerability

    Severity

    5.1MEDIUMCVSS 4.0 · citrix.com

    Attack probability (EPSS)

    3.48%89th pct

    KEV dates

    added due
  9. CVE-2025-5777Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalogransomware use: known

    Citrix · NetScaler ADC and Gateway

    Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

    Severity

    9.3CRITICALCVSS 4.0 · citrix.com

    Attack probability (EPSS)

    99.972%100th pct

    KEV dates

    added due
  10. CVE-2025-6543Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · NetScaler ADC and Gateway

    Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability

    Severity

    9.2CRITICALCVSS 4.0 · citrix.com

    Attack probability (EPSS)

    10.6%96th pct

    KEV dates

    added due
  11. CVE-2023-6549Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · NetScaler ADC and NetScaler Gateway

    Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

    Severity

    7.5HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    57.6%99.1th pct

    KEV dates

    added due
  12. CVE-2023-6548Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Citrix · NetScaler ADC and NetScaler Gateway

    Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    3.19%88th pct

    KEV dates

    added due

Citrix products in the catalog

Among the most recent entries, the products that appear most often are:

  • NetScaler5 entries
  • NetScaler ADC and NetScaler Gateway3 entries
  • Session Recording2 entries
  • NetScaler ADC and Gateway2 entries

Product names are the ones CISA uses in the catalog. To check a specific Citrix CVE that is not on this page, use the CVE lookup: it shows the record, the affected versions and the EPSS score even when the CVE is not in KEV.

Fixed versions and workarounds are published by the vendor: Citrix security bulletins.

Other vendors

Questions

How many Citrix vulnerabilities are known to be exploited?

The CISA KEV catalog, version 2026.10.02, lists 26 Citrix vulnerabilities as of 3 Oct 2026. CISA marks 7 of them as known to be used in ransomware campaigns.

What is the most recent Citrix entry in KEV?

CVE-2026-88772 (Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability), added on 27 Sep 2026 with a due date of 30 Sep 2026 for US federal agencies, as of the collection of 3 Oct 2026.

Does this page list every Citrix CVE?

No. It lists only the Citrix CVEs that CISA has confirmed as exploited. Citrix publishes many more CVEs that are not in KEV; look up any of them by identifier in the CVE lookup to see its record and EPSS score.

In what order should Citrix vulnerabilities be patched?

Everything on this page is already confirmed as exploited, so all of it is urgent where the product is in use. Within the list, entries marked with known ransomware use and those with the highest EPSS come first in the "Risk" order; internet-facing systems should go before internal ones.

Related sections