References https://nvd.nist.gov/vuln/detail/CVE-2019-19781 https://support.citrix.com/article/CTX267679 https://unit42.paloaltonetworks.com/exploits-in-the-wild-for-citrix-adc-and-citrix-gateway-directory-traversal-vulnerability-cve-2019-19781/ https://www.mdsec.co.uk/2020/01/deep-dive-in-to-citrix-adc-remote-code-execution-cve-2019-19781/ https://www.rapid7.com/blog/post/2020/01/17/active-exploitation-of-citrix-netscaler-cve-2019-19781-what-you-need-to-know/ https://github.com/trustedsec/cve-2019-19781 https://www.citrix.com/blogs/2019/12/27/citrix-adc-citrix-gateway-cve-2019-19781-vulnerability/ https://www.exploit-db.com/exploits/47930 https://www.tenable.com/cve/CVE-2019-19781 https://www.cve.org/CVERecord?id=CVE-2019-19781 https://github.com/mpgn/CVE-2019-19781 https://www.citrix.com/blogs/2020/01/24/citrix-releases-final-fixes-for-cve-2019-19781/
Related VulnerabilitiesPoCCVE-2026-26265: Discourse - Private User Field Disclosure via Directory Items IDORPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path TraversalPoCCVE-2026-44177: Kirby CMS 5.3.0-5.4.0 - Path TraversalWordPress Directory Kit 插件敏感信息泄露漏洞(CVE-2025-13920)PoCCVE-2024-1708: ConnectWise ScreenConnect <= 23.9.7 - Path TraversalPoCCVE-2026-54917: SeaweedFS <= 4.29 - Path Traversal File Write畅捷通T+系统 AccountExtendRuleController接口处存在反序列化漏洞PoCCVE-2026-25895: FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File WritePoCCVE-2026-55224: MineAdmin < 3.2.0-alpha.2 - Plugin Path Traversal to RCEPoCnodogsplash-lfi: Nodogsplash - Directory TraversalPoCCVE-2025-71324: Flowise - Path TraversalPoCCVE-2026-34908: UniFi OS - Authentication Bypass via Path Traversal (..%2f)PoCCVE-2026-53519: Nezha Dashboard < 2.0.13 - Path Traversal