Vulnerabilities
Summary — last 7 days
New vulnerabilities3,338▲ 363 vs. last week
Critical / high1,493▲ 135 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 119 vs. last week
77 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (5.8) | 0.42% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 11/12/2024 | 6/17/2026 | Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources OR the appliance must be configured as an Auth Server (AAA… | |
| Analyzed | High (8.4) | 0.56% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 11/12/2024 | 6/17/2026 | Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway… | |
| Analyzed | Medium (5.1) | 0.55% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 7/10/2024 | 6/17/2026 | Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway | |
| Analyzed | High (7.2) | 0.76% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 7/10/2024 | 6/17/2026 | Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler | |
| Analyzed | High (7.5) | 58% | ⚠ Active exploitation | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 1/17/2024 | 6/17/2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read | |
| Analyzed | High (8.8) | 3.2% | ⚠ Active exploitation | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 1/17/2024 | 6/17/2026 | Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface. | |
| Modified | High (7.5) | 0.89% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/27/2023 | 6/17/2026 | Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server | |
| Analyzed | High (7.5) | 100% | ⚠ Active exploitation | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/10/2023 | 7/31/2026 | Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | |
| Modified | High (8) | 1.3% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 7/19/2023 | 6/17/2026 | Privilege Escalation to root administrator (nsroot) | |
| Modified | Medium (6.1) | 2.6% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 7/19/2023 | 6/17/2026 | Reflected Cross-Site Scripting (XSS) | |
| Analyzed | Critical (9.8) | 100% | ⚠ Active exploitation | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 7/19/2023 | 8/5/2026 | Unauthenticated remote code execution | |
| Modified | High (8.1) | 0.84% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler Gateway | 8/5/2021 | 6/17/2026 | A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session. | |
| Modified | High (7.5) | 0.94% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler GatewayCitrix Sd-wan Wanop | 8/5/2021 | 6/17/2026 | A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the… | |
| Modified | Medium (6.5) | 3.0% | — | Citrix GatewayCitrix Netscaler GatewayCitrix Application Delivery Controller Firmware | 6/16/2021 | 6/17/2026 | Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a… | |
| Modified | Medium (6.5) | 0.42% | — | Citrix GatewayCitrix Netscaler GatewayCitrix Application Delivery Controller FirmwareCitrix Sd-wan Wanop | 6/16/2021 | 6/17/2026 | Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from… | |
| Modified | High (8.8) | 1.4% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler GatewayCitrix Sd-wan Wanop | 9/18/2020 | 6/17/2026 | Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1… | |
| Modified | High (7.5) | 1.6% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler GatewayCitrix Sd-wan Wanop | 9/18/2020 | 6/17/2026 | Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1… | |
| Modified | Medium (6.1) | 0.93% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler Gateway | 9/18/2020 | 6/17/2026 | Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a,… | |
| Modified | Medium (6.1) | 0.97% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop | 7/10/2020 | 6/17/2026 | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in Stored Cross-Site Scripting (XSS). | |
| Modified | High (8.8) | 1.8% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway Firmware | 7/10/2020 | 6/17/2026 | Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary commands. | |
| Analyzed | Medium (4.3) | 26% | ⚠ Active exploitation | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop | 7/10/2020 | 6/17/2026 | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users. | |
| Analyzed | Medium (6.5) | 33% | ⚠ Active exploitation | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop+1 | 7/10/2020 | 6/17/2026 | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users. | |
| Modified | Medium (6.5) | 11% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop | 7/10/2020 | 6/17/2026 | Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download. | |
| Analyzed | Medium (6.5) | 88% | ⚠ Active exploitation | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop | 7/10/2020 | 6/17/2026 | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints. | |
| Modified | Medium (6.1) | 26% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop | 7/10/2020 | 6/17/2026 | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS). |