Citrix vulnerabilities under active exploitation
8 CVEs on this page carry evidence of exploitation.
Which Citrix vulnerabilities are being exploited?
8 of them are in the CISA KEV catalog.
5 were added to KEV in the last 90 days.
- CVE-2026-25089 In KEV since 2026-07-16 · EPSS 74% · No fix identified here
- CVE-2026-39808 In KEV since 2026-07-16 · No fix identified here
- CVE-2026-15409 In KEV since 2026-07-14 · No fix identified here
- CVE-2026-15410 In KEV since 2026-07-14 · No fix identified here
- CVE-2026-0257 In KEV since 2026-05-29 · EPSS 94% · No fix identified here
- CVE-2026-3055 In KEV since 2026-03-30 · No fix identified here
- CVE-2025-5777 In KEV since 2025-07-10 · EPSS 100.0% · Used in ransomware · No fix identified here
- CVE-2024-42009 In KEV since 2025-06-09 · EPSS 80% · No fix identified here
Which of them have a fix?
We cannot name a fix for any of them.
For the rest we hold no patch identifier, which is not the same as no patch existing.
What PlainSec published about Citrix
Which Citrix products this page tracks
- Citrix
- Citrix ADC
- Citrix NetScaler
- Citrix Virtual Apps
- Citrix Virtual Apps and Desktops
- Citrix Workspace
- Citrix XenApp
- NetScaler
KEV and EPSS are re-checked daily. Page last updated 2026-08-06.