# Citrix vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 10 Citrix CVEs, 6 in the CISA Known Exploited Vulnerabilities catalog, 4 used in ransomware campaigns, linked to 29 tracked threat campaigns and 12 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 10 Citrix CVEs published between 2019-12-15 and 2026-03-15. The busiest month was 2023-07 (3 new CVEs). 6 of them (60%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 10 of 10 tracked Citrix CVEs.

- [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781) — CRITICAL 9.8 · KEV · Ransomware · EPSS 94.4% · 2019-12-27
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966) — CRITICAL 9.4 · KEV · Ransomware · EPSS 94.3% · 2023-10-10
- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519) — CRITICAL 9.8 · KEV · Ransomware · EPSS 93.8% · 2023-07-19
- [CVE-2026-3055](https://intel.threadlinqs.com/cve/CVE-2026-3055) — CRITICAL 9.3 · KEV · EPSS 89.7% · 2026-03-23
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777) — HIGH 7.5 · KEV · Ransomware · EPSS 62.3% · 2025-06-17
- [CVE-2025-7775](https://intel.threadlinqs.com/cve/CVE-2025-7775) — CRITICAL 9.8 · KEV · EPSS 5.7% · 2025-08-26
- [CVE-2025-5775](https://intel.threadlinqs.com/cve/CVE-2025-5775) — CRITICAL 9.1 · EPSS 72.4%
- [CVE-2023-3466](https://intel.threadlinqs.com/cve/CVE-2023-3466) — HIGH 8.3 · EPSS 1.1% · 2023-07-19
- [CVE-2023-3467](https://intel.threadlinqs.com/cve/CVE-2023-3467) — HIGH 8 · EPSS 0.4% · 2023-07-19
- [CVE-2026-4368](https://intel.threadlinqs.com/cve/CVE-2026-4368) — HIGH 7.7 · EPSS 0% · 2026-03-23

## Products affected

Threadlinqs normalises CPE and CNA product records across all 10 CVEs; 8 distinct Citrix products are affected. The most frequently affected:

- Netscaler Gateway — 10 CVEs
- Netscaler Application Delivery Controller — 7 CVEs
- NetScaler ADC — 2 CVEs
- Application Delivery Controller — 1 CVE
- Application Delivery Controller Firmware — 1 CVE
- Gateway — 1 CVE
- Gateway Firmware — 1 CVE
- Netscaler Gateway Firmware — 1 CVE

## Threat activity

29 tracked threat campaigns reference Citrix products or exploit Citrix CVEs; the 25 most recent are listed.

- [Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated Large-Scale Attacks, incl. CVE-2025-7775 Citrix NetScaler](https://intel.threadlinqs.com/threat/TL-2026-2881) — HIGH — 2026-10-03
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — CRITICAL — 2026-09-27
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — CRITICAL — 2026-09-27
- [2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)](https://intel.threadlinqs.com/threat/TL-2026-2125) — HIGH — 2026-08-23
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — HIGH — 2026-08-21
- [AI-Assisted "HTTP Terminator" Uncovers Novel HTTP Desync Techniques and Apache Traffic Server Zero-Day (CVE-2026-63078)](https://intel.threadlinqs.com/threat/TL-2026-1961) — HIGH — 2026-08-09
- [GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334 Organizations](https://intel.threadlinqs.com/threat/TL-2026-1917) — HIGH — 2026-08-06
- [Multiple Vulnerabilities in Citrix XenServer 8.4 and 9 Enable Guest-to-Host Escalation and Denial of Service (CVE-2026-42492, CVE-2026-62428, CVE-2026-62431, CVE-2026-62432, CVE-2026-62434, CVE-2026-62435, CVE-2026-62436)](https://intel.threadlinqs.com/threat/TL-2026-1781) — HIGH — 2026-07-31
- [AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groups](https://intel.threadlinqs.com/threat/TL-2026-1761) — MEDIUM — 2026-07-29
- [Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2 (CVE-2025-5777) Exploitation Wave](https://intel.threadlinqs.com/threat/TL-2026-1729) — CRITICAL — 2026-07-27
- [Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1774) — MEDIUM — 2026-07-27
- [Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands](https://intel.threadlinqs.com/threat/TL-2026-1710) — MEDIUM — 2026-07-22
- [CVE-2026-32746: Pre-Auth BSS Buffer Overflow in GNU inetutils telnetd LINEMODE SLC Handling](https://intel.threadlinqs.com/threat/TL-2026-1515) — HIGH — 2026-07-19
- [CitrixBleed 2 (CVE-2025-5777) Weaponized by Initial Access Broker for DragonForce Ransomware Deployment](https://intel.threadlinqs.com/threat/TL-2026-1150) — CRITICAL — 2026-07-09
- [CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest Memory Disclosure (CVE-2026-8451) Exploited Within 24 Hours of Disclosure](https://intel.threadlinqs.com/threat/TL-2026-1078) — CRITICAL — 2026-07-02
- [Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1086) — CRITICAL — 2026-07-02
- [FortiBleed Credential-Harvesting Campaign Against 430,000 FortiGate Firewalls Feeds INC Ransom and Lynx Ransomware Operations](https://intel.threadlinqs.com/threat/TL-2026-1090) — CRITICAL — 2026-07-02
- [CVE-2026-8451: Memory Overread in Citrix NetScaler ADC/Gateway SAML IdP ('CitrixBleed'-class, CVSS 8.8) — Exploited Within 24 Hours of Disclosure](https://intel.threadlinqs.com/threat/TL-2026-1092) — HIGH — 2026-07-02
- [Black Basta Ransomware Operation - Organizational Breakdown & 2025 Shutdown](https://intel.threadlinqs.com/threat/TL-2026-1015) — CRITICAL — 2026-06-30
- [CitrixBleed 2.0: CVE-2026-8451 NetScaler SAML IDP Memory Overread Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1140) — CRITICAL — 2026-06-30
- [Kyber Ransomware: Post-Quantum Hybrid Encryption Operation Targeting Windows & VMware ESXi](https://intel.threadlinqs.com/threat/TL-2026-0412) — CRITICAL — 2026-04-22
- [The Gentlemen Ransomware Operationalizes SystemBC SOCKS5 Botnet of 1,570+ Corporate Hosts for Double-Extortion Operations](https://intel.threadlinqs.com/threat/TL-2026-0399) — HIGH — 2026-04-20
- [CitrixBleed 3 — CVE-2026-3055 & CVE-2026-4368 NetScaler ADC/Gateway Memory Overread and Session Hijack](https://intel.threadlinqs.com/threat/TL-2026-0384) — CRITICAL — 2026-04-17
- [Device Code Phishing Surge — 37x Increase Driven by EvilTokens and VENOM PhaaS Kits Targeting Microsoft 365](https://intel.threadlinqs.com/threat/TL-2026-0323) — HIGH — 2026-04-06
- [CVE-2026-3055 & CVE-2026-4368: Citrix NetScaler ADC/Gateway Pre-Auth Memory Overread and Session Mixup](https://intel.threadlinqs.com/threat/TL-2026-0294) — CRITICAL — 2026-03-28

## Threat actors targeting Citrix

Named threat actors attributed to campaigns that involve Citrix products or CVEs, with the number of linked campaigns:

- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 2 campaigns
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 2 campaigns
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1 campaign
- [Anubis](https://intel.threadlinqs.com/actor/Anubis) — 1 campaign
- [APT29](https://intel.threadlinqs.com/actor/APT29) — 1 campaign
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 1 campaign
- [Clop](https://intel.threadlinqs.com/actor/Clop) — 1 campaign
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 1 campaign
- [EvilTokens PhaaS Operators](https://intel.threadlinqs.com/actor/EvilTokens%20PhaaS%20Operators) — 1 campaign
- [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) — 1 campaign
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 1 campaign
- [Midnight Blizzard](https://intel.threadlinqs.com/actor/Midnight%20Blizzard) — 1 campaign

## How to prioritise Citrix patching

This order follows the data Threadlinqs holds for Citrix, not a generic severity checklist:

- 6 of 10 Citrix CVEs (60%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781), [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966), [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519).
- 4 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2025-5775](https://intel.threadlinqs.com/cve/CVE-2025-5775) (72.4%), [CVE-2023-3466](https://intel.threadlinqs.com/cve/CVE-2023-3466) (1.1%), [CVE-2023-3467](https://intel.threadlinqs.com/cve/CVE-2023-3467) (0.4%).
- 6 CVEs score Critical and 4 High on CVSS v3 (maximum 9.8, average 8.9); sequence these after KEV and high-EPSS items.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/citrix
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
