Citrix Gateway
16 CVEs tracked. 6 of them are in CISA KEV.
This hub aggregates every CVE we track for Citrix Gateway, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
Citrix Gateway CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 16 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High6
- Medium6
Latest CVEs
The 15 most recently published vulnerabilities affecting Citrix Gateway.
- CVE-2023-4967Denial of service8.2
- CVE-2023-4966Unauthenticated sensitive information disclosure9.4
- CVE-2023-3467Privilege Escalation to root administrator (nsroot) 8.0
- CVE-2023-3466Reflected Cross-Site Scripting (XSS) 8.3
- CVE-2023-3519Unauthenticated remote code execution9.8
- CVE-2023-24487Arbitrary file read6.3
- CVE-2023-24488Cross site scripting6.1
- CVE-2019-18177In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 an...6.5
- CVE-2022-27518Unauthenticated remote arbitrary code execution9.8
- CVE-2022-27510Unauthorized access to Gateway user capabilities 9.8
- CVE-2022-27513Remote desktop takeover via phishing8.3
- CVE-2021-22956An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface ac...7.5
- CVE-2021-22955A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to ca...7.5
- CVE-2020-8196Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 1...4.3
- CVE-2020-8195Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and...6.5
Product grouping is registry-driven, with AI assist and human review. How it works