Vulnerability record · CVE-2019-19781 · published 27 December 2019
CVE-2019-19781: Citrix ADC and Gateway directory traversal enabling code execution
Citrix · Application Delivery Controller Firmware
Citrix Application Delivery Controller (ADC) and Gateway versions 10.5, 11.1, 12.0, 12.1, and 13.0 contain a directory traversal flaw (CWE-22). The traversal is reachable over the network without authentication and has been chained to remote code execution, making it a severe risk to internet-facing appliances.
Description
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated network reachability, KEV listing with known ransomware use, and near-maximum EPSS make this an urgent remediation target.
What it is
Citrix Application Delivery Controller (ADC) and Gateway versions 10.5, 11.1, 12.0, 12.1, and 13.0 contain a directory traversal flaw (CWE-22). The traversal is reachable over the network without authentication and has been chained to remote code execution, making it a severe risk to internet-facing appliances.
Impact
An unauthenticated attacker can traverse paths on the appliance and, per public advisories, escalate to remote code execution. This yields full compromise of the appliance, including confidentiality, integrity, and availability impact.
Attack surface
Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N) required. Any internet-exposed Citrix ADC or Gateway management/data interface is a candidate entry point.
Exploitation
Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS probability is 0.99999 (percentile 0.99998). Multiple third-party advisories describe remote code execution, indicating active exploitation in the wild.
What to do
- Apply the vendor updates referenced in Citrix advisory CTX267027 for all affected ADC and Gateway versions.
- If immediate patching is not possible, apply Citrix's published mitigation steps and restrict management interfaces from the internet.
- Place ADC/Gateway management and VPN endpoints behind network access controls and monitor for anomalous traversal patterns.
- Rotate credentials and inspect appliances for signs of compromise before returning them to service.
- Track CISA KEV remediation due date (2022-05-03) and confirm closure.
Detection
- Search web/proxy logs for path traversal sequences (e.g., ../) targeting Citrix ADC/Gateway endpoints.
- Monitor for unexpected process creation or file writes on the appliance consistent with post-exploitation.
- Alert on outbound connections from ADC/Gateway appliances to unknown hosts.
- Review authentication and admin activity logs for unauthorized access or configuration changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-19781 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-19781 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-19781), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.