CVE-2019-19781

ENISA EUVD: EUVD-2019-9380 ↗
Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 14 articles

EPSS Score

Source: FIRST.org · 2026-05-24
94.44%
probability
This CVE has a 94.44% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.1

Source: NVD
9.8
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

Attack Intelligence

Exploits & PoC

trustedsec/cve-2019-19781

This is a tool published for the Citrix ADC (NetScaler) vulnerability. We are only disclosing this due to others publishing the exploit code first.

572
projectzeroindia/CVE-2019-19781

Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [ CVE-2019-19781 ]

368
mpgn/CVE-2019-19781

CVE-2019-19781 - Remote Code Execution on Citrix ADC Netscaler exploit

160
MalwareTech/CitrixHoneypot

Detect and log CVE-2019-19781 scan and exploitation attempts.

119
cisagov/check-cve-2019-19781

Test a host for susceptibility to CVE-2019-19781

109
mandiant/ioc-scanner-CVE-2019-19781

Indicator of Compromise Scanner for CVE-2019-19781

94
jas502n/CVE-2019-19781

Citrix ADC Remote Code Execution

84
citrix/ioc-scanner-CVE-2019-19781

Indicator of Compromise Scanner for CVE-2019-19781

58
aqhmal/CVE-2019-19781

Automated script for Citrix ADC scanner (CVE-2019-19781) using hosts retrieved from Shodan API. You must have a Shodan account to use this script.

11
w4fz5uck5/CVE-2019-19781-CitrixRCE

Citrix Unauthorized Remote Code Execution Attacker - CVE-2019-19781

10
10 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
85%
EPSS 94.44%
CVSS v3.1 9.8
Mentions 14
Last Seen May 08, 2025

CNA Information

Analyst Note

CVE-2019-19781 is a critical Citrix ADC/Gateway directory traversal vulnerability (CVSS 9.8) published 2019-12-27. CERT-EU issued a security advisory in early 2020 labeling it critical, and this vulnerability became widely exploited in the wild shortly after disclosure, before patches were fully available across deployments. The rapid exploitation and critical severity align with zero-day characteristics, though specific timing confirmation is limited by available article excerpts.

Threat Actors 12

APT 29
apt_group Information theft and espionage 🇷🇺 RU
Cron
apt_group 🇷🇺 RU
Kinsing
apt_group 🇷🇺 RU
Tick
apt_group Information theft and espionage 🇨🇳 CN
APT3
apt_group Information theft and espionage 🇨🇳 CN
TeamTNT
apt_group 🇩🇪 DE
Cuboid Sandstorm
apt_group 🇮🇷 IR
Tortoiseshell
apt_group Information theft and espionage 🇮🇷 IR
Gray Sandstorm
apt_group 🇮🇷 IR
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Red October
apt_group 🇷🇺 RU
Iron Group
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 05, 2026