Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability
n/a — n/a
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
9.8
100.0%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- Dec 27, 2019
- Modified
- Aug 12, 2026
- Added to KEV
- Nov 3, 2021
- Federal patch due
- May 3, 2022
CISA required action
Apply updates per vendor instructions.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2019-19781, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- trustedsec/cve-2019-19781★ 573
This is a tool published for the Citrix ADC (NetScaler) vulnerability. We are only disclosing this due to others publishing the exploit code first.
updated Jul 16, 2026
- projectzeroindia/CVE-2019-19781★ 367
Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [ CVE-2019-19781 ]
updated Jul 16, 2026
- mpgn/CVE-2019-19781★ 158
CVE-2019-19781 - Remote Code Execution on Citrix ADC Netscaler exploit
updated Aug 26, 2026
- MalwareTech/CitrixHoneypot★ 119
Detect and log CVE-2019-19781 scan and exploitation attempts.
updated Aug 5, 2026
- cisagov/check-cve-2019-19781★ 109
Test a host for susceptibility to CVE-2019-19781
updated Aug 4, 2025
- mandiant/ioc-scanner-CVE-2019-19781★ 94
Indicator of Compromise Scanner for CVE-2019-19781
updated Feb 16, 2025
- jas502n/CVE-2019-19781★ 85
Citrix ADC Remote Code Execution
updated Jun 22, 2026
- citrix/ioc-scanner-CVE-2019-19781★ 58
Indicator of Compromise Scanner for CVE-2019-19781
updated Sep 8, 2024
References
How this class of flaw gets exploited
Frequently asked questions
What is CVE-2019-19781?
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
How severe is CVE-2019-19781?
CVE-2019-19781 has a CVSS base score of 9.8 out of 10 (CVSS 3.1).
Is CVE-2019-19781 actively exploited in the wild?
Yes. CVE-2019-19781 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Nov 3, 2021, meaning CISA has confirmed evidence of active exploitation. It is also flagged as used in ransomware campaigns.
What is the EPSS score for CVE-2019-19781?
100.0% - meaning FIRST.org's EPSS model estimates a 100.0% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2019-19781?
Yes - a public Nuclei template referencing CVE-2019-19781 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2019-19781?
CVE-2019-19781 is classified under CWE-22 (CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
Cross-checked against
Impactr finds and proves whether CVE-2019-19781 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist