CVE-2019-11550: Citrix NetScaler SD-WAN

Medium severity, CVSS 5.9. EPSS: 0.6% chance of exploitation in the next 30 days.

Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation.

Affected products

  • Citrix NetScaler SD-WAN: from 9.0.0, up to and including 9.3.6; from 10.0.0, before 10.0.7 (fixed in 10.0.7)
  • Citrix SD-WAN: from 10.1.0, up to and including 10.1.2; from 10.2.0, before 10.2.1 (fixed in 10.2.1)

Published 2019-05-08. Last modified 2026-06-17.