Vulnerabilities

Summary — last 7 days

New vulnerabilities3,338▲ 363 vs. last week
Critical / high1,493▲ 135 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 119 vs. last week
–

77 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedMedium (5.8)0.42%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway11/12/20246/17/2026
Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources OR the appliance must be configured as an Auth Server (AAA…
AnalyzedHigh (8.4)0.56%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway11/12/20246/17/2026
Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway…
AnalyzedMedium (5.1)0.55%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway7/10/20246/17/2026
Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway
AnalyzedHigh (7.2)0.76%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway7/10/20246/17/2026
Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler
AnalyzedHigh (7.5)58%⚠ Active exploitationCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway1/17/20246/17/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
AnalyzedHigh (8.8)3.2%⚠ Active exploitationCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway1/17/20246/17/2026
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
ModifiedHigh (7.5)0.89%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway10/27/20236/17/2026
Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server
AnalyzedHigh (7.5)100%⚠ Active exploitationCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway10/10/20237/31/2026
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
ModifiedHigh (8)1.3%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway7/19/20236/17/2026
Privilege Escalation to root administrator (nsroot)
ModifiedMedium (6.1)2.6%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway7/19/20236/17/2026
Reflected Cross-Site Scripting (XSS)
AnalyzedCritical (9.8)100%⚠ Active exploitationCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway7/19/20238/5/2026
Unauthenticated remote code execution
ModifiedHigh (8.1)0.84%—Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler Gateway8/5/20216/17/2026
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
ModifiedHigh (7.5)0.94%—Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler GatewayCitrix Sd-wan Wanop8/5/20216/17/2026
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the…
ModifiedMedium (6.5)3.0%—Citrix GatewayCitrix Netscaler GatewayCitrix Application Delivery Controller Firmware6/16/20216/17/2026
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a…
ModifiedMedium (6.5)0.42%—Citrix GatewayCitrix Netscaler GatewayCitrix Application Delivery Controller FirmwareCitrix Sd-wan Wanop6/16/20216/17/2026
Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from…
ModifiedHigh (8.8)1.4%—Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler GatewayCitrix Sd-wan Wanop9/18/20206/17/2026
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1…
ModifiedHigh (7.5)1.6%—Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler GatewayCitrix Sd-wan Wanop9/18/20206/17/2026
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1…
ModifiedMedium (6.1)0.93%—Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler Gateway9/18/20206/17/2026
Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a,…
ModifiedMedium (6.1)0.97%—Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop7/10/20206/17/2026
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in Stored Cross-Site Scripting (XSS).
ModifiedHigh (8.8)1.8%—Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway Firmware7/10/20206/17/2026
Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary commands.
AnalyzedMedium (4.3)26%⚠ Active exploitationCitrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop7/10/20206/17/2026
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
AnalyzedMedium (6.5)33%⚠ Active exploitationCitrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop+17/10/20206/17/2026
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.
ModifiedMedium (6.5)11%—Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop7/10/20206/17/2026
Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download.
AnalyzedMedium (6.5)88%⚠ Active exploitationCitrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop7/10/20206/17/2026
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.
ModifiedMedium (6.1)26%—Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop7/10/20206/17/2026
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).