An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
Published: 2020-01-17
Following the release of exploit scripts for a critical flaw in Citrix Application Delivery Controller (ADC) and Gateway, attackers launch attacks against vulnerable hosts, while Citrix announces release date for patches UPDATE 01/24/2020: This blog post has been updated to reflect the availability of patches released by Citrix. Background Attacks Increase After Exploit Scripts Released
Published: 2020-01-11
Attackers are actively probing for vulnerable Citrix Application Delivery Controller (ADC) and Gateway hosts, while multiple proof-of-concept scripts are released, emphasizing the importance of mitigating this flaw immediately.
Published: 2019-12-23
Citrix urges customers to apply mitigation steps for CVE-2019-19781, a remote code execution vulnerability exploitable through specially crafted HTTP requests to vulnerable devices.
https://www.kb.cert.org/vuls/id/619785
https://forms.gle/eDf3DXZAv96oosfj6
http://packetstormsecurity.com/files/155972/Citrix-ADC-Gateway-Path-Traversal.html
https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-215a
https://www.tenable.com/cyber-exposure/tenable-2022-threat-landscape-report
https://www.tenable.com/cyber-exposure/a-look-inside-the-ransomware-ecosystem
https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-117a
https://www.tenable.com/cyber-exposure/2021-threat-landscape-retrospective
https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a
https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-296a
https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-259a
https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-133a
https://www.ncsc.gov.uk/files/Advisory-further-TTPs-associated-with-SVR-cyber-actors.pdf
https://www.cisa.gov/uscert/ncas/alerts/aa20-296a#revisions
https://www.ncsc.gov.uk/files/Advisory-APT29-targets-COVID-19-vaccine-development-V1-1.pdf
https://www.mandiant.com/resources/blog/nice-try-501-ransomware-not-implemented
https://www.tenable.com/blog/frequently-asked-questions-about-iranian-cyber-operations
https://www.tenable.com/blog/from-bugs-to-breaches-25-significant-cves-as-mitre-cve-turns-25
https://www.tenable.com/blog/aa23-215a-2022s-top-routinely-exploited-vulnerabilities
https://www.tenable.com/blog/examining-the-treat-landscape
https://www.tenable.com/blog/one-year-later-what-can-we-learn-from-zerologon
https://www.tenable.com/blog/how-covid-19-response-is-expanding-the-cyberattack-surface
https://github.com/chengbochuan3/CVE-Network-Device
https://github.com/enjoylife96962930-a11y/bug-bounty-series-2026
https://github.com/Lanexus/cve-scanner
https://github.com/MohammedAbdulAhadSaud/DotSlash
https://github.com/ericrihm/edge-security-ground-truth
https://github.com/flags-alt/abyss-c2
https://github.com/cyber-green/CVE_REPORT_2026
https://github.com/THU-HJY/CVE-Honeypot
https://github.com/hakimkt/CitrixScope-Citrix-Vulnerability-Intelligence-Scanner
https://github.com/J3ff-R3y/network-scanner-cmdb
https://github.com/hermestoola/bb-hunter-pro
https://github.com/autocode07/cisagov__check-cve-2019-19781.4142e02b
https://github.com/pondoksiber/Catatan_CVE
https://github.com/hyunjin0334/CVE-2019-19781
https://github.com/citrixgitoff/-ioc-scanner-CVE-2019-19781
https://github.com/zerobytesecure/CVE-2019-19781
https://github.com/0xget/cve-2001-1473
https://github.com/34zY/APT-Backpack
https://github.com/k-fire/CVE-2019-19781-exploit
https://github.com/Vulnmachines/Ctirix_RCE-CVE-2019-19781
https://github.com/andripwn/CVE-2019-19781
https://github.com/w4fz5uck5/CVE-2019-19781-CitrixRCE
https://github.com/nmanzi/webcvescanner
https://github.com/r4ulcl/CVE-2019-19781
https://github.com/RaulCalvoLaorden/CVE-2019-19781
https://github.com/0xams/citrixvulncheck
https://github.com/Azeemering/CVE-2019-19781-DFIR-Notes
https://github.com/L4r1k/CitrixNetscalerAnalysis
https://github.com/x1sec/citrix-honeypot
https://github.com/robhax/citrix-honeypot
https://github.com/citrix/ioc-scanner-CVE-2019-19781
https://github.com/mandiant/ioc-scanner-CVE-2019-19781
https://github.com/digitalgangst/massCitrix
https://github.com/ynsmroztas/citrix.sh
https://github.com/redscan/CVE-2019-19781
https://github.com/LeapBeyond/cve_2019_19781
https://github.com/j81blog/ADC-19781
https://github.com/DanielWep/CVE-NetScalerFileSystemCheck
https://github.com/digitalshadows/CVE-2019-19781_IOCs
https://github.com/zgelici/CVE-2019-19781-Checker
https://github.com/mekhalleh/citrix_dir_traversal_rce
https://github.com/MalwareTech/CitrixHoneypot
https://github.com/aqhmal/CVE-2019-19781
https://github.com/x1sec/CVE-2019-19781
https://github.com/robhax/CVE-2019-19781
https://github.com/jamesjguthrie/Shitrix-CVE-2019-19781
https://github.com/JamesG-Zero/Shitrix-CVE-2019-19781
https://github.com/x1sec/citrixmash_scanner
https://github.com/robhax/citrixmash_scanner
https://github.com/becrevex/Citrix_CVE-2019-19781
https://github.com/oways/CVE-2019-19781
https://github.com/mpgn/CVE-2019-19781
https://github.com/ianxtianxt/CVE-2019-19781
https://github.com/cisagov/check-cve-2019-19781
https://github.com/projectzeroindia/CVE-2019-19781
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-19781
https://twitter.com/bad_packets/status/1215431625766424576
https://support.citrix.com/article/CTX267027
https://badpackets.net/over-25000-citrix-netscaler-endpoints-vulnerable-to-cve-2019-19781/
Published: 2019-12-27
Updated: 2026-08-12
Known Exploited Vulnerability (KEV)
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99999
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Concern