Vendor
NetScaler vulnerabilities
70 advisories tracked, 20 exploited in the wild according to CISA, 22 published in 2026.
Data refreshed 11 Oct 2026
Patch now
Exploited in the last two years (CISA KEV), or a 10%+ chance of exploitation in the next 30 days (EPSS).
CVE-2026-88779NetScaler ADC and Gateway
Memory overflow vulnerability leading to Denial of ServiceCVE-2026-88772NetScaler ADC and Gateway
Memory overflow vulnerability leading to Remote Code Execution or Denial of ServiceCVE-2026-88771NetScaler ADC and Gateway
A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commandsCVE-2026-19490NetScaler ADC and Gateway
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490CVE-2026-8452NetScaler ADC and Gateway
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of ServiceCVE-2026-3055NetScaler ADC and Gateway
Insufficient input validation leading to memory overread
Show all 15Show fewer
CVE-2025-12101NetScaler ADC and Gateway
Cross-Site Scripting (XSS)CVE-2025-7775NetScaler ADC and Gateway
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of ServiceCVE-2025-5777NetScaler ADC and Gateway
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overreadCVE-2025-6543NetScaler ADC and Gateway
Memory overflow vulnerability leading to unintended control flow and Denial of ServiceCVE-2025-4365Console, SDX and Agent
NetScaler Console and NetScaler SDX (SVM) - Arbitrary file readCVE-2024-12284Console, SDX and Agent
Authenticated privilege escalationCVE-2024-6235Console, SDX and Agent
Sensitive information disclosureCVE-2023-24488NetScaler ADC and Gateway
Cross site scriptingCVE-2022-27511Console, SDX and Agent
Corruption of the system by a remote, unauthenticated user potentially leading to the reset of the administrator password
Products covered
Select a product to see only its advisories.
All tracked advisories
Newest first. Full analysis marks the CVEs we've written up in depth; the rest link to an automatic summary.
| Published | CVE | Product | Issue | Severity | EPSS | Exploited |
|---|---|---|---|---|---|---|
| CVE-2026-107406 | NetScaler ADC and Gateway | Memory overflow vulnerability leading to Remote Code Execution or Denial of Service | CRITICAL 9.5 | 0.47% | – | |
| CVE-2026-88779Full analysis | NetScaler ADC and Gateway | Memory overflow vulnerability leading to Denial of Service | HIGH 8.7 | 0.59% | Yes | |
| CVE-2026-88777 | NetScaler ADC and Gateway | Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service | HIGH 8.8 | 0.38% | – | |
| CVE-2026-88775 | NetScaler ADC and Gateway | Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service | HIGH 8.8 | 0.38% | – | |
| CVE-2026-88774 | NetScaler ADC and Gateway | Feature policy bypass due to improper HTTP URL based expression usage | HIGH 7 | 0.24% | – | |
| CVE-2026-88772 | NetScaler ADC and Gateway | Memory overflow vulnerability leading to Remote Code Execution or Denial of Service | CRITICAL 9.5 | 1.3% | Yes | |
| CVE-2026-88771Full analysis | NetScaler ADC and Gateway | A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands | CRITICAL 9.5 | 1.1% | Yes | |
| CVE-2026-88773 | NetScaler ADC and Gateway | HTTP Request Smuggling | CRITICAL 9.3 | 0.36% | – | |
| CVE-2026-88776 | NetScaler ADC and Gateway | Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service | HIGH 8.8 | 0.38% | – | |
| CVE-2026-88778 | NetScaler ADC and Gateway | TCP Initial Sequence Number (ISN) prediction | HIGH 8.8 | 0.38% | – | |
| CVE-2026-19490 | NetScaler ADC and Gateway | NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 | CRITICAL 9.3 | 23% | Yes | |
| CVE-2026-19489 | NetScaler ADC and Gateway | Vulnerability in NetScaler ADC and NetScaler Gateway. | HIGH 8.8 | 3.2% | – | |
| CVE-2026-53565 | NetScaler ADC and Gateway | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges | HIGH 8.5 | 0.17% | – | |
| CVE-2026-53566 | NetScaler ADC and Gateway | Out-of-bounds memory read | MEDIUM 6.8 | 0.18% | – | |
| CVE-2026-10817 | NetScaler ADC and Gateway | Insufficient input validation leading to memory overread | MEDIUM 6.9 | 0.56% | – | |
| CVE-2026-8452 | NetScaler ADC and Gateway | Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service | HIGH 8.8 | 1.0% | Yes | |
| CVE-2026-10816 | NetScaler ADC and Gateway | Arbitrary File Read (Unauthenticated) | HIGH 7.1 | 0.58% | – | |
| CVE-2026-13474 | NetScaler ADC and Gateway | Denial of service via malformed HTTP/2 requests | HIGH 8.7 | 0.56% | – | |
| CVE-2026-8451 | NetScaler ADC and Gateway | Insufficient input validation leading to memory overread | HIGH 8.8 | 0.50% | – | |
| CVE-2026-8655 | NetScaler ADC and Gateway | Multiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of Service | HIGH 8.8 | 0.63% | – | |
| CVE-2026-4368 | NetScaler ADC and Gateway | Race Condition leading to User Session Mixup | HIGH 7.7 | 0.29% | – | |
| CVE-2026-3055 | NetScaler ADC and Gateway | Insufficient input validation leading to memory overread | CRITICAL 9.3 | 4.0% | Yes | |
| CVE-2025-12101 | NetScaler ADC and Gateway | Cross-Site Scripting (XSS) | MEDIUM 5.9 | 25% | – | |
| CVE-2025-8424 | NetScaler ADC and Gateway | Improper access control on the NetScaler Management Interface | HIGH 8.7 | 3.3% | – | |
| CVE-2025-7776 | NetScaler ADC and Gateway | Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service | HIGH 8.8 | 8.2% | – | |
| CVE-2025-7775 | NetScaler ADC and Gateway | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service | CRITICAL 9.2 | 20% | Yes | |
| CVE-2025-6759 | Console, SDX and Agent | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges | HIGH 7.3 | 0.25% | – | |
| CVE-2025-6543 | NetScaler ADC and Gateway | Memory overflow vulnerability leading to unintended control flow and Denial of Service | CRITICAL 9.2 | 11% | Yes | |
| CVE-2025-0320 | NetScaler ADC and Gateway | Citrix Secure Access - Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges | HIGH 8.6 | 0.15% | – | |
| CVE-2025-4365 | Console, SDX and Agent | NetScaler Console and NetScaler SDX (SVM) - Arbitrary file read | MEDIUM 6.9 | 11% | – | |
| CVE-2025-5349 | NetScaler ADC and Gateway | NetScaler ADC and NetScaler Gateway - Improper access control on the NetScaler Management Interface | HIGH 8.7 | 6.2% | – | |
| CVE-2025-5777 | NetScaler ADC and Gateway | NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread | CRITICAL 9.3 | 100% | Yes · ransomware | |
| CVE-2025-1223 | NetScaler ADC and Gateway | An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data | MEDIUM 5.8 | 0.16% | – | |
| CVE-2025-1222 | NetScaler ADC and Gateway | An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data | MEDIUM 5.8 | 0.16% | – | |
| CVE-2024-12284 | Console, SDX and Agent | Authenticated privilege escalation | HIGH 8.8 | 13% | – | |
| CVE-2024-8535 | NetScaler ADC and Gateway | Authenticated user can access unintended user capabilities | MEDIUM 5.8 | 0.42% | – | |
| CVE-2024-8534 | NetScaler ADC and Gateway | Memory safety vulnerability leading to memory corruption and Denial of Service | HIGH 8.4 | 0.56% | – | |
| CVE-2024-6677 | Console, SDX and Agent | Privilege escalation in uberAgent | HIGH 7.3 | 0.22% | – | |
| CVE-2024-6235 | Console, SDX and Agent | Sensitive information disclosure | CRITICAL 9.4 | 21% | – | |
| CVE-2024-5492 | NetScaler ADC and Gateway | Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites | MEDIUM 5.1 | 0.55% | – | |
| CVE-2024-6151 | Console, SDX and Agent | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges | HIGH 8.5 | 0.21% | – | |
| CVE-2024-6236 | Console, SDX and Agent | Denial of Service | HIGH 7.1 | 0.74% | – | |
| CVE-2024-5491 | NetScaler ADC and Gateway | Denial of Service | HIGH 7.2 | 0.76% | – | |
| CVE-2023-6549 | NetScaler ADC and Gateway | NetScaler ADC and NetScaler Gateway Buffer Overflow | HIGH 8.2 | 58% | Yes | |
| CVE-2023-6548 | NetScaler ADC and Gateway | NetScaler ADC and NetScaler Gateway Code Injection | MEDIUM 5.5 | 3.2% | Yes | |
| CVE-2023-4967 | NetScaler ADC and Gateway | Denial of service | HIGH 8.2 | 0.89% | – | |
| CVE-2023-4966 | NetScaler ADC and Gateway | Unauthenticated sensitive information disclosure | CRITICAL 9.4 | 100% | Yes · ransomware | |
| CVE-2023-3467 | NetScaler ADC and Gateway | Privilege Escalation to root administrator (nsroot) | HIGH 8 | 1.3% | – | |
| CVE-2023-3466 | NetScaler ADC and Gateway | Reflected Cross-Site Scripting (XSS) | HIGH 8.3 | 2.6% | – | |
| CVE-2023-3519 | NetScaler ADC and Gateway | NetScaler ADC and NetScaler Gateway Code Injection | CRITICAL 9.8 | 100% | Yes · ransomware | |
| CVE-2023-24492 | NetScaler ADC and Gateway | A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, coul… | CRITICAL 9.6 | 0.88% | – | |
| CVE-2023-24491 | NetScaler ADC and Gateway | A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited,… | HIGH 7.8 | 0.20% | – | |
| CVE-2023-24490 | Console, SDX and Agent | Users with only access to launch VDA applications can launch an unauthorized desktop | MEDIUM 6.3 | 0.30% | – | |
| CVE-2023-24487 | NetScaler ADC and Gateway | Arbitrary file read | MEDIUM 6.3 | 1.1% | – | |
| CVE-2023-24488 | NetScaler ADC and Gateway | Cross site scripting | MEDIUM 6.1 | 81% | – | |
| CVE-2022-27518 | NetScaler ADC and Gateway | Unauthenticated remote arbitrary code execution | CRITICAL 9.8 | 6.7% | Yes | |
| CVE-2022-27510 | NetScaler ADC and Gateway | Unauthorized access to Gateway user capabilities | CRITICAL 9.8 | 1.1% | – | |
| CVE-2022-27513 | NetScaler ADC and Gateway | Remote desktop takeover via phishing | HIGH 8.3 | 0.29% | – | |
| CVE-2022-27516 | NetScaler ADC and Gateway | User login brute force protection functionality bypass | MEDIUM 5.3 | 0.64% | – | |
| CVE-2022-27509 | NetScaler ADC and Gateway | Unauthenticated redirection to a malicious website | – | 0.52% | – | |
| CVE-2022-27511 | Console, SDX and Agent | Corruption of the system by a remote, unauthenticated user potentially leading to the reset of the administrator password | – | 12% | – | |
| CVE-2022-27512 | Console, SDX and Agent | Temporary disruption of the ADM license service | – | 0.98% | – | |
| CVE-2022-27507 | NetScaler ADC and Gateway | Authenticated denial of service | MEDIUM 6.5 | 0.98% | – | |
| CVE-2022-27508 | NetScaler ADC and Gateway | Unauthenticated denial of service | HIGH 7.5 | 1.0% | – | |
| CVE-2020-8196 | NetScaler ADC and Gateway | ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure | MEDIUM 4.3 | 26% | Yes | |
| CVE-2020-8195 | NetScaler ADC and Gateway | ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure | MEDIUM 6.5 | 33% | Yes | |
| CVE-2020-8193 | NetScaler ADC and Gateway | ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass | MEDIUM 6.5 | 88% | Yes | |
| CVE-2019-19781 | NetScaler ADC and Gateway | ADC, Gateway, and SD-WAN WANOP Appliance Code Execution | CRITICAL 9.8 | 100% | Yes · ransomware | |
| CVE-2019-12989 | NetScaler ADC and Gateway | SD-WAN and NetScaler SQL Injection | CRITICAL 9.8 | 95% | Yes | |
| CVE-2019-12991 | NetScaler ADC and Gateway | SD-WAN and NetScaler Command Injection | HIGH 8.8 | 74% | Yes |
Sources: NetScaler security advisories, CISA KEV and FIRST EPSS. Severity is the vendor's own rating.