Vendor

NetScaler vulnerabilities

70 advisories tracked, 20 exploited in the wild according to CISA, 22 published in 2026.

Data refreshed 11 Oct 2026

Patch now

Exploited in the last two years (CISA KEV), or a 10%+ chance of exploitation in the next 30 days (EPSS).

Show all 15Show fewer

Products covered

Select a product to see only its advisories.

All tracked advisories

Newest first. Full analysis marks the CVEs we've written up in depth; the rest link to an automatic summary.

PublishedCVEProductIssueSeverityEPSSExploited
CVE-2026-107406NetScaler ADC and GatewayMemory overflow vulnerability leading to Remote Code Execution or Denial of ServiceCRITICAL 9.50.47%–
CVE-2026-88779Full analysisNetScaler ADC and GatewayMemory overflow vulnerability leading to Denial of ServiceHIGH 8.70.59%Yes
CVE-2026-88777NetScaler ADC and GatewayMemory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of ServiceHIGH 8.80.38%–
CVE-2026-88775NetScaler ADC and GatewayMemory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of ServiceHIGH 8.80.38%–
CVE-2026-88774NetScaler ADC and GatewayFeature policy bypass due to improper HTTP URL based expression usageHIGH 70.24%–
CVE-2026-88772NetScaler ADC and GatewayMemory overflow vulnerability leading to Remote Code Execution or Denial of ServiceCRITICAL 9.51.3%Yes
CVE-2026-88771Full analysisNetScaler ADC and GatewayA remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commandsCRITICAL 9.51.1%Yes
CVE-2026-88773NetScaler ADC and GatewayHTTP Request SmugglingCRITICAL 9.30.36%–
CVE-2026-88776NetScaler ADC and GatewayMemory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of ServiceHIGH 8.80.38%–
CVE-2026-88778NetScaler ADC and GatewayTCP Initial Sequence Number (ISN) predictionHIGH 8.80.38%–
CVE-2026-19490NetScaler ADC and GatewayNetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490CRITICAL 9.323%Yes
CVE-2026-19489NetScaler ADC and GatewayVulnerability in NetScaler ADC and NetScaler Gateway.HIGH 8.83.2%–
CVE-2026-53565NetScaler ADC and GatewayLocal Privilege escalation allows a low-privileged user to gain SYSTEM privilegesHIGH 8.50.17%–
CVE-2026-53566NetScaler ADC and GatewayOut-of-bounds memory readMEDIUM 6.80.18%–
CVE-2026-10817NetScaler ADC and GatewayInsufficient input validation leading to memory overreadMEDIUM 6.90.56%–
CVE-2026-8452NetScaler ADC and GatewayMemory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of ServiceHIGH 8.81.0%Yes
CVE-2026-10816NetScaler ADC and GatewayArbitrary File Read (Unauthenticated)HIGH 7.10.58%–
CVE-2026-13474NetScaler ADC and GatewayDenial of service via malformed HTTP/2 requestsHIGH 8.70.56%–
CVE-2026-8451NetScaler ADC and GatewayInsufficient input validation leading to memory overreadHIGH 8.80.50%–
CVE-2026-8655NetScaler ADC and GatewayMultiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of ServiceHIGH 8.80.63%–
CVE-2026-4368NetScaler ADC and GatewayRace Condition leading to User Session MixupHIGH 7.70.29%–
CVE-2026-3055NetScaler ADC and GatewayInsufficient input validation leading to memory overreadCRITICAL 9.34.0%Yes
CVE-2025-12101NetScaler ADC and GatewayCross-Site Scripting (XSS)MEDIUM 5.925%–
CVE-2025-8424NetScaler ADC and GatewayImproper access control on the NetScaler Management InterfaceHIGH 8.73.3%–
CVE-2025-7776NetScaler ADC and GatewayMemory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of ServiceHIGH 8.88.2%–
CVE-2025-7775NetScaler ADC and GatewayMemory overflow vulnerability leading to Remote Code Execution and/or Denial of ServiceCRITICAL 9.220%Yes
CVE-2025-6759Console, SDX and AgentLocal Privilege escalation allows a low-privileged user to gain SYSTEM privilegesHIGH 7.30.25%–
CVE-2025-6543NetScaler ADC and GatewayMemory overflow vulnerability leading to unintended control flow and Denial of ServiceCRITICAL 9.211%Yes
CVE-2025-0320NetScaler ADC and GatewayCitrix Secure Access - Local Privilege escalation allows a low-privileged user to gain SYSTEM privilegesHIGH 8.60.15%–
CVE-2025-4365Console, SDX and AgentNetScaler Console and NetScaler SDX (SVM) - Arbitrary file readMEDIUM 6.911%–
CVE-2025-5349NetScaler ADC and GatewayNetScaler ADC and NetScaler Gateway - Improper access control on the NetScaler Management InterfaceHIGH 8.76.2%–
CVE-2025-5777NetScaler ADC and GatewayNetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overreadCRITICAL 9.3100%Yes · ransomware
CVE-2025-1223NetScaler ADC and GatewayAn attacker can gain application privileges in order to perform limited modification and/or read arbitrary dataMEDIUM 5.80.16%–
CVE-2025-1222NetScaler ADC and GatewayAn attacker can gain application privileges in order to perform limited modification and/or read arbitrary dataMEDIUM 5.80.16%–
CVE-2024-12284Console, SDX and AgentAuthenticated privilege escalationHIGH 8.813%–
CVE-2024-8535NetScaler ADC and GatewayAuthenticated user can access unintended user capabilitiesMEDIUM 5.80.42%–
CVE-2024-8534NetScaler ADC and GatewayMemory safety vulnerability leading to memory corruption and Denial of ServiceHIGH 8.40.56%–
CVE-2024-6677Console, SDX and AgentPrivilege escalation in uberAgentHIGH 7.30.22%–
CVE-2024-6235Console, SDX and AgentSensitive information disclosureCRITICAL 9.421%–
CVE-2024-5492NetScaler ADC and GatewayOpen redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websitesMEDIUM 5.10.55%–
CVE-2024-6151Console, SDX and AgentLocal Privilege escalation allows a low-privileged user to gain SYSTEM privilegesHIGH 8.50.21%–
CVE-2024-6236Console, SDX and AgentDenial of ServiceHIGH 7.10.74%–
CVE-2024-5491NetScaler ADC and GatewayDenial of ServiceHIGH 7.20.76%–
CVE-2023-6549NetScaler ADC and GatewayNetScaler ADC and NetScaler Gateway Buffer OverflowHIGH 8.258%Yes
CVE-2023-6548NetScaler ADC and GatewayNetScaler ADC and NetScaler Gateway Code InjectionMEDIUM 5.53.2%Yes
CVE-2023-4967NetScaler ADC and GatewayDenial of serviceHIGH 8.20.89%–
CVE-2023-4966NetScaler ADC and GatewayUnauthenticated sensitive information disclosureCRITICAL 9.4100%Yes · ransomware
CVE-2023-3467NetScaler ADC and GatewayPrivilege Escalation to root administrator (nsroot)HIGH 81.3%–
CVE-2023-3466NetScaler ADC and GatewayReflected Cross-Site Scripting (XSS)HIGH 8.32.6%–
CVE-2023-3519NetScaler ADC and GatewayNetScaler ADC and NetScaler Gateway Code InjectionCRITICAL 9.8100%Yes · ransomware
CVE-2023-24492NetScaler ADC and GatewayA vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, coul…CRITICAL 9.60.88%–
CVE-2023-24491NetScaler ADC and GatewayA vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited,…HIGH 7.80.20%–
CVE-2023-24490Console, SDX and AgentUsers with only access to launch VDA applications can launch an unauthorized desktopMEDIUM 6.30.30%–
CVE-2023-24487NetScaler ADC and GatewayArbitrary file readMEDIUM 6.31.1%–
CVE-2023-24488NetScaler ADC and GatewayCross site scriptingMEDIUM 6.181%–
CVE-2022-27518NetScaler ADC and GatewayUnauthenticated remote arbitrary code executionCRITICAL 9.86.7%Yes
CVE-2022-27510NetScaler ADC and GatewayUnauthorized access to Gateway user capabilitiesCRITICAL 9.81.1%–
CVE-2022-27513NetScaler ADC and GatewayRemote desktop takeover via phishingHIGH 8.30.29%–
CVE-2022-27516NetScaler ADC and GatewayUser login brute force protection functionality bypassMEDIUM 5.30.64%–
CVE-2022-27509NetScaler ADC and GatewayUnauthenticated redirection to a malicious website–0.52%–
CVE-2022-27511Console, SDX and AgentCorruption of the system by a remote, unauthenticated user potentially leading to the reset of the administrator password–12%–
CVE-2022-27512Console, SDX and AgentTemporary disruption of the ADM license service–0.98%–
CVE-2022-27507NetScaler ADC and GatewayAuthenticated denial of serviceMEDIUM 6.50.98%–
CVE-2022-27508NetScaler ADC and GatewayUnauthenticated denial of serviceHIGH 7.51.0%–
CVE-2020-8196NetScaler ADC and GatewayADC, Gateway, and SD-WAN WANOP Appliance Information DisclosureMEDIUM 4.326%Yes
CVE-2020-8195NetScaler ADC and GatewayADC, Gateway, and SD-WAN WANOP Appliance Information DisclosureMEDIUM 6.533%Yes
CVE-2020-8193NetScaler ADC and GatewayADC, Gateway, and SD-WAN WANOP Appliance Authorization BypassMEDIUM 6.588%Yes
CVE-2019-19781NetScaler ADC and GatewayADC, Gateway, and SD-WAN WANOP Appliance Code ExecutionCRITICAL 9.8100%Yes · ransomware
CVE-2019-12989NetScaler ADC and GatewaySD-WAN and NetScaler SQL InjectionCRITICAL 9.895%Yes
CVE-2019-12991NetScaler ADC and GatewaySD-WAN and NetScaler Command InjectionHIGH 8.874%Yes

Sources: NetScaler security advisories, CISA KEV and FIRST EPSS. Severity is the vendor's own rating.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.