C

Citrix Systems

Delivers remote access and digital workspaces

Overview

Company Historically Provides H1B Sponsorship

Citrix focuses on remote access and digital workspace software that lets people securely access apps and data from anywhere, on any device. Its tools deliver app delivery, secure access, and centralized workspace management so employees can stay productive regardless of location or network. The products work by providing remote connectivity, virtualization and app delivery layers, and management features through licenses, subscriptions, and support services, all under the Cloud Software Group umbrella. Compared with competitors, Citrix emphasizes broad reach across large enterprises and small businesses with a strong focus on secure, reliable access to applications and data, and comprehensive workspace management across diverse networks and devices. The company’s goal is to help organizations maintain operational efficiency and security in a mobile and distributed work environment by ensuring apps stay available, data remains protected, and employees remain productive.

Work here?Claim your company

About Citrix Systems

Simplify's Rating
Why Citrix Systems is rated
C-
Rated C on Competitive Edge
Rated C on Growth Potential
Rated D+ on Differentiation

Industries

Enterprise SoftwareCybersecurity

Company Size

1,001-5,000

Company Stage

Debt Financing

Total Funding

$1.8B

Headquarters

Fort Lauderdale, Florida

Founded

1989

Get referred to Citrix Systems

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Citrix acquired Numecent on Sept. 1 2026, strengthening application delivery resilience.
  • Session Insights meets rising AI governance demand in regulated enterprises this quarter.
  • Citrix-managed cloud services get direct vendor upgrades, reducing patch friction for some customers.

What critics are saying

  • CISA and GTIG reported active exploitation of NetScaler zero-days since early September 2026.
  • Over 20,000 exposed NetScaler instances create a huge installed-base compromise risk.
  • Cloud Software Group layoffs and licensing backlash push customers toward VMware alternatives before 2027.

What makes Citrix Systems unique

  • Sept. 2026 Numecent adds Cloudpaging across physical and virtual Windows endpoints.
  • Citrix Session Insights, launched Sept. 15 2026, records browser sessions for humans and agents.
  • Citrix still owns NetScaler, giving it deep control over remote access and load balancing.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$1.8B

Above

Industry Average

Funded Over

7 Rounds

Notable Investors:
Debt funding comparison data is currently unavailable. We're working to provide this information soon!
Debt Funding Comparison Coming Soon

Benefits

Parental Leave

Growth & Insights and Company News

Headcount

6 month growth

↓ -35%

1 year growth

↓ -35%

2 year growth

↓ -35%
News4Hackers
Oct 5th, 2026
Alleged shiny Hunters Leader Arrested in Jordan.

Alleged shiny Hunters Leader Arrested in Jordan. Post Views: 14 Alleged ShinyHunters Leader Arrested in Jordan A suspect linked to the ShinyHunters extortion group has been detained in Jordan and is assisting the FBI with its investigation. The individual, identified as Saif al-Din Khader, also known by the alias Rey, is a young cybercriminal from Amman who has also been associated with the Scattered Lapsus$ Hunters collective. Authorities have not disclosed the exact location of his detention. The arrest occurred following the group's recent breach of the FBI's public job portal, FBIJobs.gov, which was defaced to assert the theft of 2-3 terabytes of data. ShinyHunters reportedly shared a sample list containing details of 5,000 FBI employees, claiming to possess personal and medical information for all current and former FBI personnel. In parallel, Dutch law enforcement apprehended a 24-year-old suspect in Amsterdam as part of the FBI's probe into ShinyHunters. The FBI confirmed the arrest, stating the individual was implicated in hacking over 140 organizations and facilitating at least $70 million in extortion payments. While Dutch authorities and the FBI have not disclosed the suspect's identity, independent reports indicate the person is Pepijn van der Stap, a hacker convicted in 2023 for cyberattacks and extortion. He was serving a three-year sentence before being released on supervised probation. Khader allegedly attributed the FBI breach to van der Stap by deploying a defacement image featuring the Pokémon character Umbreon, a nickname van der Stap used in prior extortion activities, as reported by investigative journalist Brian Krebs. "More arrests are on the table," FBI Director Kash Patel stated on X. The investigation continues as law enforcement agencies work to dismantle the group's operations and recover stolen data. Additional developments in the cybersecurity landscape include the disruption of the KillSec ransomware operation and the identification of an alleged teenage leader. Meanwhile, the U.S. Treasury has targeted a prominent ATM malware developer and his network. Other recent threats involve the exploitation of vulnerabilities in Fortinet FortiMail, Zimbra, and WatchGuard systems, with urgent patches recommended. A zero-day in Citrix NetScaler was exploited before public disclosure, and a critical flaw in Cisco Catalyst SD-WAN devices was addressed. Security professionals are also monitoring the expansion of SharePoint exploitation by the Warlock group, as well as AI-driven attacks leveraging zero-days in Zammad. Over 500,000 exposed credentials were discovered on GitHub, prompting warnings about insecure code practices. Updates to Chrome and Firefox have resolved more than 100 vulnerabilities, while a critical code injection flaw in WatchGuard Fireware was patched. In related news, the Trump administration has appointed Jay Clayton as the new national intelligence director to lead a federal AI task force. Meanwhile, cybersecurity firms are addressing emerging risks through advanced threat detection and proactive mitigation strategies.

Computer Weekly
Sep 29th, 2026
Cyber authorities issue alerts over exploitation of Citrix vulns.

Cyber authorities issue alerts over exploitation of Citrix vulns. The latest vulnerabilities to be uncovered in the frequently-targeted Citrix NetScaler product lines were being exploited well-before disclosure, prompting disquiet. Published: 29 Sep 2026 16:40 Two distinct remote zero-day vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and Gateway are coming under rapid exploitation from threat actors, prompting fresh alerts from government cyber agencies in the UK, the Netherlands, and the US. The flaws in the frequently-targeted NetScaler product set, which run access, load balancing and authentication at the network edge, are among a tranche of fixes released by Citrix on Sunday 27 September, and should be patched immediately. The core issues in scope are flaws tracked as CVE-2026-88771, which arises from improper input validation and enables an unauthenticated actor to execute arbitrary commands, and CVE-2026-88772, which arises from a memory overflow condition and enables both denial-of-service or remote code execution (RCE) attacks. The issues affect versions 13.1 and 14.1 of NetScaler ADC and Gateway prior to 13.1-64.23 and 14.1-73.37 respectively, NetScaler ADC FIPS prior to version 14.1-73/37 FIPS, and NetScaler ADC FIPS and NDcPP prior to version 13.1-37.279, said Citrix. The UK's National Cyber Security Centre (NCSC) said: "The NCSC is working to understand the impact of these vulnerabilities on UK organisations." The US' Cybersecurity and Infrastructure Security Agency (Cisa) said it had added both of the most serious flaws to its Known Exploited Vulnerabilities (Kev) catalogue - with a fix deadline of Wednesday 30 September. "Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally," the agency said in a statement. The NCSC is urging organisations to familiarise themselves with the Citrix security bulletin and further information - including indicators of compromise (IoCs) - and if possible to isolate any affected systems and replace them with a new, fully up-to-date one, although it cautioned that this may cause a significant IT outage. If compromise is suspected, organisations should also preserve forensic evidence prior to applying the updates. "If you believe you have been compromised, and are in the UK, you should report it. You can also report the compromise to the vendor to assist their investigation," the NCSC added. Disclosure timeline. Citrix has subsequently faced criticism over the timeline for disclosure of the zero-days after it became apparent that Dutch NCSC had issued an alert concerning exploitation of the-day flaws in advance of the supplier's own disclosure. WatchTowr, which also broke cover ahead of Citrix and was among the first to communicate the existence of the zero-days prior to the weekend, described a "serious situation" that "should not be underestimated." As a result of this, rumours of a potential incident swirled on social media platform Reddit as IT and security teams awaited official confirmation from Citrix at the weekend. Writing on Monday 28 September, WatchTowr researcher Sina Kheirkhah commented: "Nordic Women in Tech Awards is sure there are many teams at this point having extremely tense conversations with their TAM [technical account manager], asking why an actively exploited RCE in a default configuration was communicated to the world through many channels, none of which included Citrix itself. "Nordic Women in Tech Awards is yet again dealing with a situation where the entire world apparently knew about Citrix NetScaler CVEs before Citrix had woken up or bothered to acknowledge them. "We all know that vulnerabilities exist. Code is not perfect... but communicating with your customers who pay for a solution to secure their environment feels like the bare minimum, not optional," wrote Kheirkhah. * AI accelerates exploit timelines from months to hours. Organisations must shift from patch-all to risk-based prioritisation using exploitability metrics. * Microsoft's July Patch Tuesday broke records by addressing over 600 CVEs. What does this reveal about the effect that AI models have on vulnerability and patch management? * The application of agentic AI to vulnerability management workflows has slashed mitigation times in experimental conditions, claims Sase specialist Cato Networks.

Accops
Sep 29th, 2026
5 best virtual desktop infrastructure (VDI) solutions in 2026.

5 best virtual desktop infrastructure (VDI) solutions in 2026. Windows 10 support ended on 14 October 2025. That single deadline pushed a lot of IT teams to re-examine how they deliver desktops in the first place, rather than just buying new hardware to run Windows 11. Virtual desktop infrastructure sits at the centre of that decision, because it changes where the OS actually runs and who is responsible for patching it. The VDI market has also shifted structurally in the last two years. VMware's EUC division was sold off and rebranded as Omnissa. Citrix went through a major private equity acquisition. Licensing models across the board have moved toward subscription and consumption-based pricing. None of this is cosmetic: it changes total cost of ownership, migration risk, and how many separate vendors you need for security. Below are 5 platforms IT teams are evaluating in 2026, starting with Accops VDI. * Accops VDI. Accops VDI is Accops's virtual desktop and app delivery platform, running Windows and Linux desktops as persistent, non-persistent, shared, or personal instances. It supports Nutanix, VMware, Microsoft Hyper-V, Azure, Proxmox, Red Hat OpenShift/OpenStack, and HPE's hypervisor, plus AWS, GCP, and OCI, with self-service provisioning so end users can request their own desktop without raising an IT ticket. For workload performance, Accops VDI uses Photon, its own display protocol built to keep video and audio synchronised across the inconsistent networks common in hybrid work, such as home broadband or mobile connections. It's aimed at multimedia-heavy and real-time collaboration workloads, where standard remoting protocols tend to introduce lag or audio drift. Profile management, user experience monitoring, and session recording are part of the core editions, which run from Bronze through Platinum, licensed as named-user or concurrent-user, on a perpetual or subscription basis. Accops also builds its own ZTNA gateway (HySecure) and identity, MFA, and SSO engine (HyID) in-house. Both integrate directly with Accops VDI, and combine with it into the full Digital Workspace bundle for organisations that want VDI, secure access, and identity delivered together as one solution from a single vendor. * Citrix DaaS. Citrix DaaS (from Cloud Software Group) delivers virtual apps and desktops from the cloud with a centralised management console. It includes policy-based access control, multi-factor authentication, session recording, session watermarking, and TLS/SSL encrypted delivery, and integrates with StoreFront and the Citrix Workspace app. Citrix has also introduced Citrix Aidrien, an AI-powered assistant built into Citrix Cloud that lets admins query their DaaS and NetScaler environment in natural language and get answers sourced from Citrix's own documentation and environment data. It's a mature platform with broad hypervisor and cloud support. Pricing is subscription-based, with tiers that vary by feature set, management level, and deployment model. Organisations already running Citrix infrastructure typically find it the path of least resistance, but layered secure access (equivalent to ZTNA) and identity features are managed as distinct components within the wider Citrix Platform rather than a single bundled licence. * Omnissa Horizon. Omnissa Horizon (formerly VMware Horizon, spun out of Broadcom's EUC division and now owned by KKR) delivers virtual desktops and apps using Instant Clone technology for fast provisioning, App Volumes for real-time application delivery, and Dynamic Environment Manager for policy control. The Blast Extreme protocol is now the primary connection protocol; the legacy PCoIP protocol is being phased out of new Horizon releases. Horizon runs on-premises on VMware vSphere or via Horizon Cloud on AWS, Azure, Google Cloud, IBM Cloud, and Oracle Cloud. It delivers the most value when paired with the wider VMware stack, since vCenter handles infrastructure management. Effective 4 May 2026, Omnissa raised list prices on Horizon licences, with a smaller increase for bundles that include VMware vSphere Foundation for VDI and a noticeably steeper one for bundles that don't. The change applies only to new and expansion purchases; existing renewals are unaffected. * Microsoft Azure virtual desktop (AVD). AVD is a cloud-native desktop and app virtualisation service running entirely on Azure. Microsoft manages the control plane; the customer manages the session host virtual machines. Microsoft states AVD is the only platform offering Windows 11 and Windows 10 Enterprise multi-session, which lets several users share one VM and reduces the number of virtual machines needed for a pooled desktop environment. Pricing is consumption-based: organisations pay for the underlying Azure compute, storage, and networking by the second, with no separate AVD service fee for users already licensed for Microsoft 365 or Windows Enterprise. Identity runs through Microsoft Entra ID, with Active Directory sync common in hybrid environments. Because AVD is a PaaS offering rather than a packaged product, organisations without in-house Azure networking and identity expertise usually need a management layer or partner (Nerdio, Parallels RAS, or similar) on top of it to run day-to-day operations smoothly. * Amazon WorkSpaces. Amazon WorkSpaces is a fully managed DaaS offering from AWS, delivering persistent Windows or Linux desktops, with WorkSpaces Applications available separately for streaming individual apps rather than full desktops. It includes multi-factor authentication, single sign-on, IP-address-based access control groups, and integrates with AWS Directory Service or an organisation's existing Active Directory. Pricing is pay-as-you-go, based on bundles that combine compute and storage, and the platform includes the technical controls organisations typically need as part of a HIPAA or PCI DSS programme, such as encryption and access logging. WorkSpaces is a strong fit for organisations already standardised on AWS, since it shares identity, networking, and billing with the rest of the AWS estate. Outside an AWS-centric environment, it's a narrower fit than platforms built to run across multiple hypervisors and clouds. Three questions worth asking before you shortlist. * Is security bundled or a separate purchase? ZTNA, MFA, and SSO from the same vendor as your VDI, whether bundled or offered as an add-on, means fewer consoles and support contracts for your team to manage. * Does it lock you into one hypervisor or cloud? Horizon delivers the most value inside VMware; AVD is Azure-only. Others are built to run across all of them. * How is it licensed, and does that fit your capex or opex plan? Perpetual, subscription, and consumption-based pricing behave very differently at renewal time. Choosing the right fit. Once security and licensing are ruled in or out, the two things that actually decide a shortlist are Linux support and migration effort. If part of your user base doesn't need Windows, a VDI solution with native Linux desktops avoids Microsoft CAL costs entirely, something worth checking against each vendor's own documentation rather than assuming. Migration timelines are the other place vendor quotes diverge from reality. Ask any shortlisted vendor to run a pilot with your actual profiles, images, and access policies before signing, not a generic demo environment. A platform that looks fastest to deploy on paper isn't always the one that's fastest to deploy with your data. Frequently asked questions. No. VDI describes the underlying architecture: virtual desktops hosted centrally and streamed to a device. DaaS describes the consumption model: the provider manages the infrastructure and sells it as a service. Most platforms in this list offer both on-premises VDI and a DaaS variant. Sep 29, 2026 Irshad Khan Senior Lead, Solution Consulting & Presales Irshad Khan is the Senior Lead for Solution Consulting and Presales at Accops, a leading provider of secure remote access and digital workspace solutions. With a practical, infrastructure-first perspective built over years of hands-on technical experience within Accops, he helps enterprises navigate the transition to secure, centralised IT environments. Irshad brings deep working knowledge of remote access architecture, IT virtualisation, and systems security, ensuring organisations can adopt modern workspace solutions with confidence. Ready to get started?

Truesec
Sep 28th, 2026
Multiple critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway.

Multiple critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. On Sept 27th, 2026, Citrix released security updates to address eight vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. * 2026-09-28 * Insight According to Citrix, the vulnerabilities include multiple remote code execution (RCE), memory corruption, HTTP request smuggling, policy bypass, denial-of-service, and TCP sequence prediction issues. Of particular concern are CVE-2026-88771 and CVE-2026-88772. Both vulnerabilities were exploited in the wild prior to the release of security updates. While patches are now available, organizations running affected NetScaler deployments should not only prioritize patching but also consider the possibility that vulnerable systems may have been compromised before remediation became available. CVE-2026-88771 is an unauthenticated remote code execution vulnerability caused by improper input validation and affects all NetScaler ADC and NetScaler Gateway deployments by default. CVE-2026-88772 is a memory overflow vulnerability that may lead to remote code execution or denial of service when DTLS is enabled, which is enabled by default on VPN virtual servers [1]. CVE. CVE-2026-88771 CVE-2026-88772 CVE-2026-88773 CVE-2026-88774 CVE-2026-88775 CVE-2026-88776 CVE-2026-88777 CVE-2026-88778 Affected products. Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37 Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23 Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279 Exploitation. Exploitation of CVE-2026-88771 and CVE-2026-88772 has been observed on unmitigated NetScaler deployments[1]. Recommended actions. Truesec recommends that customers upgrade vulnerable NetScaler appliances to fixed releases as soon as possible. NetScaler ADC and NetScaler Gateway 14.1-73.37 or later NetScaler ADC and NetScaler Gateway 13.1-64.23 or later NetScaler ADC FIPS 14.1-73.37 FIPS or later NetScaler ADC FIPS and NDcPP 13.1-37.279 or later If upgrading is not an option, please implement strict containment measures until you are able to upgrade[2]: * If your organization utilizes NetScaler Gateway solely for telework or administrative access, immediately configure upstream edge firewalls to restrict inbound traffic on TCP port 443 to verified, geographic IP ranges or corporate-managed static IPs. Completely eliminate public internet access (0.0.0.0/0) to the Gateway interface. * If NetScaler is used exclusively for application load balancing and Content Switching (without Gateway or AAA features), verify that the VPN virtual server (vserver) is completely disabled: text disable vpn vserver * If suspicious shell executions, unexpected cron tasks, or memory crash dumps in /var/crash/ are discovered, immediately isolate the appliance from the network. Take a full forensic snapshot of the disk and memory state, revoke all corporate SSL/TLS certificates and private keys hosted on the appliance, and force an organization-wide password and MFA session reset for all users who authenticated through the gateway over the preceding 30 days. Detection Truesec has observed these potential C2 IPs: 104.248.244.66 139.180.152.138 77.83.199.39 These IP addresses has been added to automated threat hunting and will be hunted for every 4 hours. References.

Nikto Online
Sep 28th, 2026
Citrix confirms 2 NetScaler zero-days after admins pulled the plug.

Citrix confirms 2 NetScaler zero-days after admins pulled the plug. 28 September 2026 Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772. Hacking & Cracking

Recently Posted Jobs

Sign up to get curated job recommendations

Citrix Systems is Hiring for 3 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs