March 25, 2022 · Applied Cybernetics Group
CVE-2021-22941 — Citrix ShareFile
known ransomware use
Citrix ShareFile Improper Access Control Vulnerability
- Added to KEV
2022-03-25- Federal due date
2022-04-15- Vendor
- Citrix
- Product
- ShareFile
- EPSS
- 99.5th percentile (score 0.885, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-22941
CISA short description
Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.
Required action
Apply updates per vendor instructions.