LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-19781: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-19781 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.

CVE-2019-19781 is a vulnerability in Citrix Application Delivery Controller (ADC), Citrix Gateway, and certain Citrix SD-WAN WANOP appliance models. It can allow an unauthenticated attacker to achieve code execution on the device. Because these products often sit at the network edge and handle remote access or application delivery, successful abuse can give an attacker a foothold into the environment. Public reporting also links this issue to ransomware activity, so organizations that still run unpatched instances should treat it as high priority and confirm current status against the vendor advisory.

How it works

The weakness is classified as CWE-22 (path traversal / improper limitation of a pathname to a restricted directory). In products of this class, path-traversal flaws typically let an attacker craft requests that escape the intended directory or resource boundary. When combined with other conditions on the appliance, that can lead to unauthorized file access or, as described for this CVE, code execution without prior authentication.

CISA summarizes the issue as an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution on Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models. Exact request patterns, endpoints, and exploit mechanics are not detailed in the facts provided here; defenders should rely on the vendor advisory and their own threat-intelligence sources rather than assuming any particular payload or sequence.

Am I affected? How to find it in your systems

These products commonly run as physical or virtual appliances in DMZs, data centers, or cloud environments, providing load balancing, SSL VPN / remote access, or WAN optimization. Inventory every Citrix ADC (formerly NetScaler), Citrix Gateway, and SD-WAN WANOP instance—including secondary, lab, and decommissioned-but-still-powered units.

How to remediate

Patching is the primary fix. Apply the updates published by Citrix for ADC, Gateway, and the affected SD-WAN WANOP models exactly as directed in the vendor advisory and in line with CISA’s required action: apply updates per vendor instructions. Schedule maintenance windows promptly; test in a non-production environment if your change process requires it, then roll out to production.

If you can't patch immediately

If an immediate upgrade is impossible, reduce exposure until you can patch:

These steps are compensating controls only; they do not replace the vendor update.

If your data may have been exposed

Actively exploited vulnerabilities of this type have been used in ransomware campaigns and can lead to full compromise of the appliance and lateral movement. If you find evidence of exploitation or cannot rule it out, follow your incident-response plan: isolate affected systems, preserve logs and disk images, rotate credentials that traversed the device, and engage forensics as needed. As a further check on personal or corporate email addresses that may appear in breach data, you can run a free exposure scan to see whether those addresses are present in known breach corpora and then take appropriate credential-reset and monitoring steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCitrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
WeaknessCWE-22
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities