CSG A.I CyberSecurity Scoring
CSG
Company Information
Website:https://www.cloud.com/
Employees number:9,661
Number of followers:37,383
NAICS:5112
Industry Type:Software Development
Homepage:cloud.com
CSG Risk Score (AI oriented)
Between 750 and 799
CSGSoftware Development
Updated:
18/07/2026
18/07/2026
760/1000
Fair
Baa
CSG Global Score (TPRM)
xxxx
CSGSoftware Development
Score locked

CSGFair
Current Score
760Baa (FAIR)
01000
3 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
760
JULY 2026
765
Vulnerability
18 Jul 2026 • CSG
Cloud Software Group: Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation
Critical Privilege Escalation Flaws in Citrix Windows Clients Disclosed
760
CRITICAL-5
CLO1784370278
Critical Privilege Escalation Flaws in Citrix Windows Clients Disclosed
Cloud Software Group has revealed two security vulnerabilities in Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, including a severe flaw enabling low-privileged attackers to gain full SYSTEM-level access on affected machines.
The most critical issue, CVE-2026-53565 (CVSS 8.5), stems from improper privilege management (CWE-269) and allows local users to escalate privileges without user interaction. The vulnerability affects both Citrix Secure Access Client and Citrix Endpoint Analysis Client, requiring no special conditions beyond standard user access. Successful exploitation grants complete control over confidentiality, integrity, and availability.
A second flaw, CVE-2026-53566 (CVSS 6.8), involves an out-of-bounds memory read (CWE-125) and affects only Citrix Secure Access Client. Exploitation requires the absence of the DNE (Deterministic Network Enhancer) driver and impacts only confidentiality.
Organizations using these clients particularly in shared workstations, VDI environments, or BYOD setups are urged to patch immediately. Recommended updates:
- Citrix Secure Access Client for Windows: Version 26.6.1.20 or later
- Citrix Endpoint Analysis Client for Windows: Version 26.5.1.7 or later
For CVE-2026-53566, administrators should verify DNE driver installation via Citrix’s documentation. The vulnerabilities were responsibly disclosed by Carlos Garrido of Pentraze Cybersecurity, allowing coordinated remediation before public release.
Privilege escalation flaws like CVE-2026-53565 pose significant risks in enterprise environments, as attackers with initial low-level access (e.g., via phishing or compromised accounts) could exploit them to seize full endpoint control. Security teams should prioritize patching and audit configurations to mitigate exposure.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JUNE 2026
765
MAY 2026
764
APRIL 2026
764
MARCH 2026
769
Vulnerability
23 Mar 2026 • CSG
Cloud Software Group: Critical NetScaler ADC and Gateway Vulnerabilities Enable Remote Attacks on Affected Systems
Critical NetScaler ADC and Gateway Vulnerabilities Patched by Cloud Software Group
764
CRITICAL-5
CLO1774312166
Critical NetScaler ADC and Gateway Vulnerabilities Patched by Cloud Software Group
Cloud Software Group has released emergency security updates for NetScaler ADC and NetScaler Gateway, addressing two high-severity vulnerabilities that could enable unauthenticated remote attacks on affected systems.
The most critical flaw, CVE-2026-3055 (CVSS 9.3), is an out-of-bounds read vulnerability in SAML Identity Provider (IDP) configurations. Exploitable without authentication or user interaction, it allows attackers to trigger memory overreads, potentially leading to system compromise. The issue was discovered internally, with no evidence of active exploitation at the time of disclosure. Administrators can check for exposure by verifying SAML IDP configurations in NetScaler settings.
The second vulnerability, CVE-2026-4368 (CVSS 7.7), involves a race condition causing session mixups in appliances configured as Gateways (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or AAA virtual servers. While exploitation requires low-privilege authentication and precise timing, successful attacks could fully compromise session confidentiality and integrity.
Affected Versions & Patches:
- CVE-2026-3055: NetScaler ADC/Gateway 14.1 before 14.1-66.59, 13.1 before 13.1-62.23, and FIPS/NDcPP before 13.1-37.262.
- CVE-2026-4368: NetScaler ADC/Gateway 14.1-66.54.
Fixed releases include 14.1-66.59 or later, 13.1-62.23 or later, and 13.1-FIPS/NDcPP 13.1.37.262 or later. The patches apply only to customer-managed deployments, as Citrix-managed cloud services and Adaptive Authentication instances have already been updated.
Given NetScaler’s widespread use in enterprise VPN and application delivery, unpatched systems pose a significant risk. Security teams are advised to prioritize updates, particularly for SAML IDP-configured appliances.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
FEBRUARY 2026
769
JANUARY 2026
769
DECEMBER 2025
769
NOVEMBER 2025
768
OCTOBER 2025
768
SEPTEMBER 2025
768
JANUARY 2024
768
Vulnerability
01 Jan 2024 • CSG
Citrix and WhatsUp Gold: INC Ransomware Uses Rust-Based Windows and Linux/ESXi Encryptors in New Attacks
INC Ransomware Emerges as a Top Global Threat, Targeting Critical Sectors with Rust-Based Encryptors
766
CRITICAL-2
PROCLO1781871843
INC Ransomware Emerges as a Top Global Threat, Targeting Critical Sectors with Rust-Based Encryptors
Since its emergence in mid-2023, INC ransomware has rapidly evolved into one of the most prolific ransomware operations, claiming over 800 victims worldwide. Operating under a Ransomware-as-a-Service (RaaS) model, the group recruits affiliates and equips them with advanced tools to scale attacks across industries.
Initially focusing on healthcare and education, INC has expanded its targeting to legal services, manufacturing, construction, and technology sectors under regulatory pressure and more likely to pay ransoms quickly. The group employs a double extortion tactic, encrypting files while threatening to leak stolen data on its leak site, compounding operational and reputational risks for victims.
A recent report from Acronis highlights significant technical advancements in INC’s toolkit. Both its Windows and Linux/ESXi encryptors have been rewritten in Rust, enabling cross-platform attacks with greater evasion capabilities. The updated Windows variant targets Veeam backup deployments, while the Linux/ESXi version optimizes encryption speed by distinguishing local disks from network shares. Both payloads use partial encryption to maintain system usability while ensuring ransom notes remain visible.
INC affiliates leverage legitimate remote access tools including CobaltStrike, AnyDesk, ScreenConnect, and TeamViewer to blend into normal IT activity. They also deploy process terminators like PsKill to disable endpoint defenses before exfiltrating data via rclone and 7-Zip. Credential theft has been refined to target salted DPAPI-encrypted Veeam backups.
The group’s influence extends beyond its core operations. Following the 2024 disruption of its source code seller, related ransomware families like Lynx and Knoba emerged with overlapping code, indicating the spread of INC’s tooling into adjacent threat groups.
Security researchers have identified multiple vulnerabilities exploited in INC attacks, including CVE-2023-3519 (Citrix NetScaler RCE), CVE-2023-4966 (Citrix Bleed), CVE-2023-35082 (SimpleHelp RMM), and CVE-2024-4885 (WhatsUp Gold RCE). Indicators of compromise (IoCs) include Rust-based encryptor hashes, abused legitimate tools, and ransom note filenames like INC-README.TXT.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CSG ??
What was CSG's A.I Rankiteo Cyber Score in July 2026 ??
What was CSG's A.I Rankiteo Cyber Score in June 2026 ??
What was CSG's A.I Rankiteo Cyber Score in May 2026 ??
What was CSG's A.I Rankiteo Cyber Score in April 2026 ??
What was CSG's A.I Rankiteo Cyber Score in March 2026 ??
What was CSG's A.I Rankiteo Cyber Score in February 2026 ??
What was CSG's A.I Rankiteo Cyber Score in January 2026 ??
What was CSG's A.I Rankiteo Cyber Score in December 2025 ??
What was CSG's A.I Rankiteo Cyber Score in November 2025 ??
What was CSG's A.I Rankiteo Cyber Score in October 2025 ??
What was CSG's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on CSG's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CSG ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CSG's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?