Known Vulnerabilities for Access Gateway by Citrix
Listed below are 10 of the newest known vulnerabilities associated with "Access Gateway" by "Citrix".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-45006 json | OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.pat... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-45001 json | OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply end... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-44994 json | OpenClaw before 2026.4.22 contains an authentication bypass vulnerability in the Control UI bootstrap config endpoint that al... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-44874 json | A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote at... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-44125 json | SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the new G... | Not Provided | 2026-05-08 | 2026-05-08 |
| CVE-2026-43585 json | OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid aft... | Not Provided | 2026-05-06 | 2026-05-07 |
| CVE-2026-43568 json | OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators to m... | Not Provided | 2026-05-05 | 2026-05-05 |
| CVE-2026-43528 json | OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive unre... | Not Provided | 2026-05-05 | 2026-05-06 |
| CVE-2026-42429 json | OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism th... | Not Provided | 2026-04-28 | 2026-04-29 |
| CVE-2026-42421 json | OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared gateway... | Not Provided | 2026-04-28 | 2026-04-29 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Citrix | Access Gateway | 4.5.5 | |||
| Application | Citrix | Access Gateway | 4.5 | |||
| Application | Citrix | Access Gateway | 4.5 | |||
| Application | Citrix | Access Gateway | 4.5 | |||
| Application | Citrix | Access Gateway | 4.2 | |||
| Application | Citrix | Access Gateway | 4.0 | |||
| Application | Citrix | Access Gateway | - |