logo

CISA Warns of Citrix RCE and Privilege Escalation Vulnerabilities Exploited in Attacks

ID: 75be8658-1deb-5568-bbdc-30158f3a46c2

STIX ID: report--75be8658-1deb-5568-bbdc-30158f3a46c2

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2025-08-26

Date Updated: 2026-04-21

Author: Florence Nightingale

...
...

CISA added three actively exploited CVEs to its KEV catalog: two Citrix Session Recording vulnerabilities enabling limited remote code execution or privilege escalation to NetworkService (requiring authenticated/intranet access), and a Git configuration-quoting/symlink vulnerability allowing arbitrary code execution; CISA urges immediate patching and federal agencies must remediate under BOD 22-01.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.