Citrix Vulnerabilities and Affected Products
Vulnerabilities associated with NetScaler ADC and NetScaler Gateway.
Products
Clear product- NetScaler ADC and NetScaler Gateway15 vulnerabilities
- SD-WAN and NetScaler7 vulnerabilities
- Citrix Workspace app for Windows5 vulnerabilities
- virtual_apps_and_desktops5 vulnerabilities
- Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance4 vulnerabilities
- Citrix Gateway, Citrix ADC4 vulnerabilities
- NetScaler ADC4 vulnerabilities
- NetScaler Gateway4 vulnerabilities
- ShareFile4 vulnerabilities
- application_delivery_controller_firmware2 vulnerabilities
- Citrix ADC and Citrix Gateway2 vulnerabilities
- Citrix Application Delivery Management (Citrix ADM)2 vulnerabilities
- Citrix Secure Access Client for Windows2 vulnerabilities
- Citrix Workspace app for HTML52 vulnerabilities
- NetScaler2 vulnerabilities
- NetScaler ADC and Gateway2 vulnerabilities
- netscaler_application_delivery_controller2 vulnerabilities
- netscaler_gateway2 vulnerabilities
- Secure Access Client for Mac2 vulnerabilities
- Secure Access Client for Windows2 vulnerabilities
- secure_access_client2 vulnerabilities
- Session Recording2 vulnerabilities
- workspace_app2 vulnerabilities
- Application Delivery Controller (ADC) and Gateway1 vulnerability
- Citrix Endpoint Analysis Client for Windows1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-8451HIGH | Insufficient input validation leading to memory overreadInsufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP CWE-125Jun 30, 2026 | CVSS8.8v4.0 | EPSS15.7% | PoCs4 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-3055CRITICAL | Insufficient input validation leading to memory overreadInsufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread | CVSS9.3v4.0 | EPSS84.5% | PoCs7 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2025-7775CRITICAL | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of ServiceMemory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS an… CWE-119Aug 26, 2025 | CVSS9.2v4.0 | EPSS19.6% | PoCs5 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-6543CRITICAL | Memory overflow vulnerability leading to unintended control flow and Denial of ServiceMemory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server CWE-119Jun 25, 2025 | CVSS9.2v4.0 | EPSS10.1% | PoCs3 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-5777CRITICAL | NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overreadInsufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | CVSS9.3v4.0 | EPSS>99.9% | PoCs28 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2024-6235CRITICAL | Sensitive information disclosureSensitive information disclosure in NetScaler Console | CVSS9.4v4.0 | EPSS21.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-6549HIGH | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow VulnerabilityImproper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read | CVSS8.2v3.1 | EPSS57.6% | PoCs0 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-6548MEDIUM | Citrix NetScaler ADC and NetScaler Gateway Code Injection VulnerabilityImproper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface. CWE-94Jan 17, 2024 | CVSS5.5v3.1 | EPSS3.19% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4967HIGH | Denial of serviceDenial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server CWE-119Oct 27, 2023 | CVSS8.2v3.1 | EPSS0.885% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2023-4966CRITICAL | Unauthenticated sensitive information disclosureSensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | CVSS9.4v3.1 | EPSS>99.9% | PoCs15 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2023-3467HIGH | Citrix ADC and Citrix Gateway Root Administrator (nsroot) Privilege EscalationPrivilege Escalation to root administrator (nsroot) CWE-269Jul 19, 2023 | CVSS8.0v3.1 | EPSS1.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3466HIGH | Citrix NetScaler ADC and NetScaler Gateway Improper Input ValidationReflected Cross-Site Scripting (XSS) | CVSS8.3v3.1 | EPSS2.79% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3519CRITICAL | Citrix NetScaler ADC and NetScaler Gateway Code Injection VulnerabilityUnauthenticated remote code execution | CVSS9.8v3.1 | EPSS99.7% | PoCs17 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2022-27518CRITICAL | Unauthenticated remote arbitrary code executionUnauthenticated remote arbitrary code execution CWE-664Dec 13, 2022 | CVSS9.8v3.1 | EPSS6.88% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-4945MEDIUM | Citrix NetScaler ADC and NetScaler Gateway Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attackers to inject arbitrary web script or HTML via the NSC_TMAC cookie. CWE-79Jun 1, 2016 | CVSS6.1v3.0 | EPSS1.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |