Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
27 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2026-88779 | Citrix | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | Severity: High CVSS 8.7 | Oct 4, 2026 | Not known |
| CVE-2026-88771 | Citrix | Citrix NetScaler Improper Input Validation Vulnerability | Severity: Critical CVSS 9.5 | Sep 27, 2026 | Not known |
| CVE-2026-88772 | Citrix | Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | Severity: Critical CVSS 9.5 | Sep 27, 2026 | Not known |
| CVE-2026-19490 | Citrix | Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability | Severity: Critical CVSS 9.3 | Sep 9, 2026 | Not known |
| CVE-2026-8452 | Citrix | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | Severity: High CVSS 8.8 | Aug 26, 2026 | Not known |
| CVE-2026-3055 | Citrix | Citrix NetScaler Out-of-Bounds Read Vulnerability | Severity: Critical CVSS 9.3 | Mar 30, 2026 | Not known |
| CVE-2025-7775 | Citrix | Citrix NetScaler Memory Overflow Vulnerability | Severity: Critical CVSS 9.2 | Aug 26, 2025 | Not known |
| CVE-2024-8068 | Citrix | Citrix Session Recording Improper Privilege Management Vulnerability | Severity: Elevated CVSS 5.1 | Aug 25, 2025 | Not known |
| CVE-2024-8069 | Citrix | Citrix Session Recording Deserialization of Untrusted Data Vulnerability | Severity: Elevated CVSS 5.1 | Aug 25, 2025 | Not known |
| CVE-2025-5777 | Citrix | Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability | Severity: Critical CVSS 9.3 | Jul 10, 2025 | Known |
| CVE-2025-6543 | Citrix | Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability | Severity: Critical CVSS 9.2 | Jun 30, 2025 | Not known |
| CVE-2023-6548 | Citrix | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | Severity: High CVSS 8.8 | Jan 17, 2024 | Not known |
| CVE-2023-6549 | Citrix | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | Severity: High CVSS 7.5 | Jan 17, 2024 | Not known |
| CVE-2023-4966 | Citrix | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | Severity: High CVSS 7.5 | Oct 18, 2023 | Known |
| CVE-2023-24489 | Citrix | Citrix Content Collaboration ShareFile Improper Access Control Vulnerability | Severity: Critical CVSS 9.8 | Aug 16, 2023 | Not known |
| CVE-2023-3519 | Citrix | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | Severity: Critical CVSS 9.8 | Jul 19, 2023 | Known |
| CVE-2022-27518 | Citrix | Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Dec 13, 2022 | Not known |
| CVE-2017-6316 | Citrix | Citrix Multiple Products Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Mar 25, 2022 | Not known |
| CVE-2019-12989 | Citrix | Citrix SD-WAN and NetScaler SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Mar 25, 2022 | Not known |
| CVE-2021-22941 | Citrix | Citrix ShareFile Improper Access Control Vulnerability | Severity: Critical CVSS 9.8 | Mar 25, 2022 | Known |
| CVE-2019-12991 | Citrix | Citrix SD-WAN and NetScaler Command Injection Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Not known |
| CVE-2019-11634 | Citrix | Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Nov 3, 2021 | Known |
| CVE-2019-19781 | Citrix | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Nov 3, 2021 | Known |
| CVE-2019-13608 | Citrix | Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability | Severity: High CVSS 7.5 | Nov 3, 2021 | Known |
| CVE-2020-8193 | Citrix | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability | Severity: Elevated CVSS 6.5 | Nov 3, 2021 | Not known |
| CVE-2020-8195 | Citrix | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability | Severity: Elevated CVSS 6.5 | Nov 3, 2021 | Not known |
| CVE-2020-8196 | Citrix | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability | Severity: Elevated CVSS 4.3 | Nov 3, 2021 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
