Exploitation timeline
Threadlinqs has recorded 10 Citrix CVEs published between and . The busiest month was 2023-07 (3 new CVEs). 6 of them (60%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 10 of 10 tracked Citrix CVEs.
- CVE-2019-19781critical 9.8KEVRansomwareEPSS 94.4%
- CVE-2023-4966critical 9.4KEVRansomwareEPSS 94.3%
- CVE-2023-3519critical 9.8KEVRansomwareEPSS 93.8%
- CVE-2026-3055critical 9.3KEVEPSS 89.7%
- CVE-2025-5777high 7.5KEVRansomwareEPSS 62.3%
- CVE-2025-7775critical 9.8KEVEPSS 5.7%
- CVE-2025-5775critical 9.1EPSS 72.4%
- CVE-2023-3466high 8.3EPSS 1.1%
- CVE-2023-3467high 8EPSS 0.4%
- CVE-2026-4368high 7.7EPSS 0%
Products affected
Threadlinqs normalises CPE and CNA product records across all 10 CVEs; 8 distinct Citrix products are affected. The most frequently affected:
- Netscaler Gateway 10 CVEs
- Netscaler Application Delivery Controller 7 CVEs
- NetScaler ADC 2 CVEs
- Application Delivery Controller 1 CVE
- Application Delivery Controller Firmware 1 CVE
- Gateway 1 CVE
- Gateway Firmware 1 CVE
- Netscaler Gateway Firmware 1 CVE
Threat activity
29 tracked threat campaigns reference Citrix products or exploit Citrix CVEs; the 25 most recent are listed.
- Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated Large-Scale Attacks, incl. CVE-2025-7775 Citrix NetScalerHIGH
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)CRITICAL
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV CatalogCRITICAL
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)HIGH
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)HIGH
- AI-Assisted "HTTP Terminator" Uncovers Novel HTTP Desync Techniques and Apache Traffic Server Zero-Day (CVE-2026-63078)HIGH
- GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334 OrganizationsHIGH
- Multiple Vulnerabilities in Citrix XenServer 8.4 and 9 Enable Guest-to-Host Escalation and Denial of Service (CVE-2026-42492, CVE-2026-62428, CVE-2026-62431, CVE-2026-62432, CVE-2026-62434, CVE-2026-62435, CVE-2026-62436)HIGH
- AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware GroupsMEDIUM
- Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2 (CVE-2025-5777) Exploitation WaveCRITICAL
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote AccessMEDIUM
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion DemandsMEDIUM
- CVE-2026-32746: Pre-Auth BSS Buffer Overflow in GNU inetutils telnetd LINEMODE SLC HandlingHIGH
- CitrixBleed 2 (CVE-2025-5777) Weaponized by Initial Access Broker for DragonForce Ransomware DeploymentCRITICAL
- CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest Memory Disclosure (CVE-2026-8451) Exploited Within 24 Hours of DisclosureCRITICAL
- Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege EscalationCRITICAL
- FortiBleed Credential-Harvesting Campaign Against 430,000 FortiGate Firewalls Feeds INC Ransom and Lynx Ransomware OperationsCRITICAL
- CVE-2026-8451: Memory Overread in Citrix NetScaler ADC/Gateway SAML IdP ('CitrixBleed'-class, CVSS 8.8) — Exploited Within 24 Hours of DisclosureHIGH
- Black Basta Ransomware Operation - Organizational Breakdown & 2025 ShutdownCRITICAL
- CitrixBleed 2.0: CVE-2026-8451 NetScaler SAML IDP Memory Overread Under Active ExploitationCRITICAL
- Kyber Ransomware: Post-Quantum Hybrid Encryption Operation Targeting Windows & VMware ESXiCRITICAL
- The Gentlemen Ransomware Operationalizes SystemBC SOCKS5 Botnet of 1,570+ Corporate Hosts for Double-Extortion OperationsHIGH
- CitrixBleed 3 — CVE-2026-3055 & CVE-2026-4368 NetScaler ADC/Gateway Memory Overread and Session HijackCRITICAL
- Device Code Phishing Surge — 37x Increase Driven by EvilTokens and VENOM PhaaS Kits Targeting Microsoft 365HIGH
- CVE-2026-3055 & CVE-2026-4368: Citrix NetScaler ADC/Gateway Pre-Auth Memory Overread and Session MixupCRITICAL
Threat actors targeting Citrix
Named threat actors attributed to campaigns that involve Citrix products or CVEs, with the number of linked campaigns:
How to prioritise Citrix patching
This order follows the data Threadlinqs holds for Citrix, not a generic severity checklist:
- 6 of 10 Citrix CVEs (60%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2019-19781, CVE-2023-4966, CVE-2023-3519.
- 4 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2025-5775 (72.4%), CVE-2023-3466 (1.1%), CVE-2023-3467 (0.4%).
- 6 CVEs score Critical and 4 High on CVSS v3 (maximum 9.8, average 8.9); sequence these after KEV and high-EPSS items.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.