← Vulnerability feed

Vulnerability record · CVE-2019-19781 · published 27 December 2019

CVE-2019-19781: Citrix ADC and Gateway directory traversal enabling code execution

Citrix · Application Delivery Controller Firmware

Citrix Application Delivery Controller (ADC) and Gateway versions 10.5, 11.1, 12.0, 12.1, and 13.0 contain a directory traversal flaw (CWE-22). The traversal is reachable over the network without authentication and has been chained to remote code execution, making it a severe risk to internet-facing appliances.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1% CWE-22 · Path traversal
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
21References
12 Aug 2026Last modified by NVD

Description

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated network reachability, KEV listing with known ransomware use, and near-maximum EPSS make this an urgent remediation target.

What it is

Citrix Application Delivery Controller (ADC) and Gateway versions 10.5, 11.1, 12.0, 12.1, and 13.0 contain a directory traversal flaw (CWE-22). The traversal is reachable over the network without authentication and has been chained to remote code execution, making it a severe risk to internet-facing appliances.

Impact

An unauthenticated attacker can traverse paths on the appliance and, per public advisories, escalate to remote code execution. This yields full compromise of the appliance, including confidentiality, integrity, and availability impact.

Attack surface

Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N) required. Any internet-exposed Citrix ADC or Gateway management/data interface is a candidate entry point.

Exploitation

Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS probability is 0.99999 (percentile 0.99998). Multiple third-party advisories describe remote code execution, indicating active exploitation in the wild.

What to do

  • Apply the vendor updates referenced in Citrix advisory CTX267027 for all affected ADC and Gateway versions.
  • If immediate patching is not possible, apply Citrix's published mitigation steps and restrict management interfaces from the internet.
  • Place ADC/Gateway management and VPN endpoints behind network access controls and monitor for anomalous traversal patterns.
  • Rotate credentials and inspect appliances for signs of compromise before returning them to service.
  • Track CISA KEV remediation due date (2022-05-03) and confirm closure.

Detection

  • Search web/proxy logs for path traversal sequences (e.g., ../) targeting Citrix ADC/Gateway endpoints.
  • Monitor for unexpected process creation or file writes on the appliance consistent with post-exploitation.
  • Alert on outbound connections from ADC/Gateway appliances to unknown hosts.
  • Review authentication and admin activity logs for unauthorized access or configuration changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-19781 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/155904/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155905/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution-Travers Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155930/Citrix-Application-Delivery-Controller-Gateway-10.5-Remote-Code-Execution.ht Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155947/Citrix-ADC-NetScaler-Directory-Traversal-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155972/Citrix-ADC-Gateway-Path-Traversal.html Third Party AdvisoryVDB Entry
https://badpackets.net/over-25000-citrix-netscaler-endpoints-vulnerable-to-cve-2019-19781/ Broken LinkThird Party Advisory
https://forms.gle/eDf3DXZAv96oosfj6 Third Party Advisory
https://support.citrix.com/article/CTX267027 Vendor Advisory
https://twitter.com/bad_packets/status/1215431625766424576 Broken LinkThird Party Advisory
https://www.kb.cert.org/vuls/id/619785 Third Party AdvisoryUS Government Resource
http://packetstormsecurity.com/files/155904/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155905/Citrix-Application-Delivery-Controller-Gateway-Remote-Code-Execution-Travers Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155930/Citrix-Application-Delivery-Controller-Gateway-10.5-Remote-Code-Execution.ht Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155947/Citrix-ADC-NetScaler-Directory-Traversal-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155972/Citrix-ADC-Gateway-Path-Traversal.html Third Party AdvisoryVDB Entry
https://badpackets.net/over-25000-citrix-netscaler-endpoints-vulnerable-to-cve-2019-19781/ Broken LinkThird Party Advisory
https://forms.gle/eDf3DXZAv96oosfj6 Third Party Advisory
https://support.citrix.com/article/CTX267027 Vendor Advisory
https://twitter.com/bad_packets/status/1215431625766424576 Broken LinkThird Party Advisory
https://www.kb.cert.org/vuls/id/619785 Third Party AdvisoryUS Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-19781 US Government Resource

Track CVE-2019-19781 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-27518Citrix ADC and Gateway unauthenticated remote code executionCVE-2022-27518 is an unauthenticated remote arbitrary code execution flaw in Citrix Application Delivery Controller (ADC) and Gateway firmware. The C…KEVEPSS 6.7%analysed6.5CVE-2020-8193Citrix ADC and Gateway improper access control allows unauthenticated endpoint accessCitrix ADC, Citrix Gateway, and Citrix SD-WAN WAN-OP contain an improper access control flaw (CWE-284/CWE-287) that lets unauthenticated users reach …KEVEPSS 88%analysed6.5CVE-2020-8195Citrix ADC and Gateway improper input validation information disclosureCitrix ADC, Citrix Gateway, and Citrix SD-WAN WAN-OP contain improper input validation that can result in limited information disclosure to low privi…KEVEPSS 33%analysed4.3CVE-2020-8196Citrix ADC and Gateway improper access control information disclosureCitrix ADC, Citrix Gateway and Citrix SD-WAN WAN-OP appliances contain an improper access control flaw (CWE-284/CWE-287) that allows limited informat…KEVEPSS 26%analysed10.0CVE-2015-5538Citrix netscaler application delivery controller firmware vulnerabilityMultiple unspecified vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 be…EPSS 3.2%9.8CVE-2022-27510Citrix gateway authentication bypass via alternate path vulnerabilityUnauthorized access to Gateway user capabilitiesEPSS 1.1%9.8CVE-2022-27516Citrix gateway improper restriction of authentication attempts vulnerabilityUser login brute force protection functionality bypassEPSS 0.64%9.8CVE-2019-18225Citrix application delivery controller firmware vulnerabilityAn issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before …EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2019-19781), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.