CVE-2019-19781Active Exploitation(citrix / application_delivery_controller)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch citrix application_delivery_controller systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • application_delivery_controller
  • application_delivery_controller_firmware
  • gateway
  • gateway_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-03-04); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
application_delivery_controllerapplication_delivery_controller_firmwaregatewaygateway_firmwarenetscaler_gatewaynetscaler_gateway_firmware

6 versions affected across 6 products

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-03-04: 1Mentions · 2026-08-09: 1Mentions · 2026-09-27: 1Mentions · 2026-09-28: 1Mentions · 2026-10-01: 1Active Exploitation · 2026-03-04: 1Patch / Workaround · 2026-09-27: 103-0408-0909-2709-2810-01
Signal classification3 categories
Active Exploitation
133.3%
General
133.3%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-041
Active Exploitation1
2026-08-091
General1
2026-09-271
Patch1
Full discourse5 posts
  • Nitin Gavhane@NitinGavhane_
    General

    @shodanhq 7/13 Vuln & CVE Filters • vuln:CVE-2021-44228 (Log4Shell) • vuln:CVE-2019-19781 • tag:ics • cloud.provider:AWS • cloud.region:us-east-1 Directly hunt known vulnerable services. #bugbounty #infosec #hacking #cybersecurity #vuln

    Post summary

    The post announces a set of CVE filters for hunting known vulnerabilities on AWS in the us-east-1 region, but contains no technical details, PoC, or exploitation information.

    10010158
    1.2K followersView on X
  • David@davidsheyi
    Active Exploitation

    1/ Chinese APT41, known for its dual role in espionage and financial crime, targets industries from telecom to healthcare. Their attacks often exploit CVE-2019-19781. #ThreatIntel #InfoSec

    Post summary

    APT41 is actively exploiting CVE‑2019‑19781 across multiple industries.

    1000044
    556 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2019-19781 Product: Citrix / Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Summary: VulnCheck reports real-world exploitation activity affecting Citrix / Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance. Evidence: Public PoC/exploit available; Ransomware use confirmed; Active exploitation reported; Severe impact class Impact: The vulnerability is associated with ransomware activity and may contribute to compromise of exposed systems. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 16 Jan 2020 Source: https://vulncheck.com/xdb/5daef00ab695 #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Citrix #ApplicationDeliveryControllerADCGatewayandSD_WANWANOPAppliance #CVE_2019_19781 #ActiveExploitation #Exploit #Ransomware #RansomwareAttack

    0000083
    226 followersView on X
  • PCMedicalist@PCMedicalist

    🧠 Engineering & Research Digest (Sep 27) CVE-2019-19781--Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities: patch Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities #CyberSecurity #InfoSec #PCMedicalist #CompSci https://t.co/pnvNLKShcs

    00000112
    158 followersView on X
  • PCMedicalist@PCMedicalist
    Patch

    🧠 Engineering & Research Digest (Sep 27) CVE-2019-19781--Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities: patch Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities #CyberSecurity #InfoSec #PCMedicalist #CompSci https://t.co/QPEZydLPEw

    Post summary

    The tweet shares a vendor FAQ resource for CVE-2019-19781 (Citrix NetScaler zero-day) that explicitly highlights patch information as a primary focus.

    00000385
    164 followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
HWcitrixapplication_delivery_controller---
OScitrixapplication_delivery_controller_firmware10.5--
OScitrixapplication_delivery_controller_firmware11.1--
OScitrixapplication_delivery_controller_firmware12.0--
OScitrixapplication_delivery_controller_firmware12.1--
OScitrixapplication_delivery_controller_firmware13.0--
HWcitrixgateway---
OScitrixgateway_firmware13.0--
HWcitrixnetscaler_gateway---
OScitrixnetscaler_gateway_firmware10.5--
OScitrixnetscaler_gateway_firmware11.1--
OScitrixnetscaler_gateway_firmware12.0--
OScitrixnetscaler_gateway_firmware12.1--

Explore more