November 3, 2021 · Applied Cybernetics Group
CVE-2019-13608 — Citrix StoreFront Server
known ransomware use
Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability
- Added to KEV
2021-11-03- Federal due date
2022-05-03- Vendor
- Citrix
- Product
- StoreFront Server
- EPSS
- 98.8th percentile (score 0.717, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2019-13608
CISA short description
Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.
Required action
Apply updates per vendor instructions.