« Back to list

Citrix

Citrix Netscaler Application Delivery Controller: vulnerabilities and CVEs

Citrix Netscaler Application Delivery Controller has 39 published vulnerabilities, 16 of them in the last 12 months. 9 are rated critical and 12 are listed by CISA as actively exploited.

CVEs39
Last 12 months16
Critical9
Actively exploited12

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-88772Critical (9.5)1.3%⚠ Active exploitationSep 27, 2026
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37…
CVE-2026-88771Critical (9.5)1.1%⚠ Active exploitationSep 27, 2026
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP;…
CVE-2026-19490Critical (9.3)7.0%⚠ Active exploitationAug 19, 2026
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
CVE-2026-8452High (8.8)1.0%⚠ Active exploitationJun 30, 2026
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or…
CVE-2026-3055Critical (9.3)4.0%⚠ Active exploitationMar 23, 2026
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
CVE-2025-7775Critical (9.2)20%⚠ Active exploitationAug 26, 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or…
CVE-2025-5777Critical (9.3)100%⚠ Active exploitationJun 17, 2025
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CVE-2025-6543Critical (9.2)11%⚠ Active exploitationJun 25, 2025
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual…
CVE-2023-6549High (7.5)58%⚠ Active exploitationJan 17, 2024
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
CVE-2023-6548High (8.8)3.2%⚠ Active exploitationJan 17, 2024
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged)…
CVE-2023-4966High (7.5)100%⚠ Active exploitationOct 10, 2023
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
CVE-2023-3519Critical (9.8)100%⚠ Active exploitationJul 19, 2023
Unauthenticated remote code execution

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-88778High (8.8)0.38%—Sep 27, 2026
Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before…
CVE-2026-88777High (8.8)0.38%—Sep 27, 2026
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and…
CVE-2026-88776High (8.8)0.38%—Sep 27, 2026
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and…
CVE-2026-88775High (8.8)0.38%—Sep 27, 2026
Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway:…
CVE-2026-88774High (7)0.24%—Sep 27, 2026
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37…
CVE-2026-88773Critical (9.3)0.36%—Sep 27, 2026
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before…
CVE-2026-88772Critical (9.5)1.3%⚠ Active exploitationSep 27, 2026
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37…
CVE-2026-88771Critical (9.5)1.1%⚠ Active exploitationSep 27, 2026
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP;…
CVE-2026-19490Critical (9.3)7.0%⚠ Active exploitationAug 19, 2026
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
CVE-2026-8655High (8.8)0.63%—Jun 30, 2026
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler…
CVE-2026-8452High (8.8)1.0%⚠ Active exploitationJun 30, 2026
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or…
CVE-2026-8451High (8.8)0.50%—Jun 30, 2026
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
CVE-2026-13474High (8.7)0.56%—Jun 30, 2026
Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on…
CVE-2026-10817Medium (6.9)0.56%—Jun 30, 2026
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the…
CVE-2026-10816High (7.1)0.58%—Jun 30, 2026
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
CVE-2026-3055Critical (9.3)4.0%⚠ Active exploitationMar 23, 2026
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
CVE-2025-7776High (8.8)6.9%—Aug 26, 2025
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN,…
CVE-2025-7775Critical (9.2)20%⚠ Active exploitationAug 26, 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or…
CVE-2025-6543Critical (9.2)11%⚠ Active exploitationJun 25, 2025
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual…
CVE-2025-5777Critical (9.3)100%⚠ Active exploitationJun 17, 2025
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CVE-2025-5349High (8.7)6.2%—Jun 17, 2025
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway
CVE-2024-8535Medium (5.8)0.42%—Nov 12, 2024
Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for…
CVE-2024-8534High (8.4)0.56%—Nov 12, 2024
Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must…
CVE-2024-5492Medium (5.1)0.55%—Jul 10, 2024
Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway
CVE-2024-5491High (7.2)0.76%—Jul 10, 2024
Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler
CVE-2023-6549High (7.5)58%⚠ Active exploitationJan 17, 2024
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
CVE-2023-6548High (8.8)3.2%⚠ Active exploitationJan 17, 2024
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged)…
CVE-2023-4967High (7.5)0.89%—Oct 27, 2023
Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server
CVE-2023-4966High (7.5)100%⚠ Active exploitationOct 10, 2023
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
CVE-2023-3467High (8)1.3%—Jul 19, 2023
Privilege Escalation to root administrator (nsroot)

📰 Related news

Other products by Citrix