NetScaler Vulnerabilities and Affected Products
Vulnerabilities associated with ADC.
Products
Clear product- ADC17 vulnerabilities
- Gateway16 vulnerabilities
- NetScaler Gateway3 vulnerabilities
- Agent2 vulnerabilities
- Console2 vulnerabilities
- NetScaler ADC2 vulnerabilities
- NetScaler Console1 vulnerability
- netscaler-adc_12.1-fips1 vulnerability
- netscaler-adc_12.1-ndcpp1 vulnerability
- netscaler-adc_13.1-fips1 vulnerability
- netscaler_console1 vulnerability
- SDX1 vulnerability
- SDX (SVM)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-13474HIGH | Denial of service via malformed HTTP/2 requestsDenial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler CWE-401Jun 30, 2026 | CVSS8.7v4.0 | EPSS0.472% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-10817MEDIUM | Insufficient input validation leading to memory overreadInsufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler CWE-125Jun 30, 2026 | CVSS6.9v4.0 | EPSS0.41% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-10816HIGH | Arbitrary File Read (Unauthenticated)Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled | CVSS7.1v4.0 | EPSS0.415% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8655HIGH | Multiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of ServiceMultiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment CWE-119Jun 30, 2026 | CVSS8.8v4.0 | EPSS0.493% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8452HIGH | Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of ServiceMemory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server CWE-119Jun 30, 2026 | CVSS8.8v4.0 | EPSS0.487% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8451HIGH | Insufficient input validation leading to memory overreadInsufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP CWE-125Jun 30, 2026 | CVSS8.8v4.0 | EPSS15.7% | PoCs4 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-3055CRITICAL | Insufficient input validation leading to memory overreadInsufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread | CVSS9.3v4.0 | EPSS84.5% | PoCs7 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-4368HIGH | Race Condition leading to User Session MixupRace Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup CWE-362Mar 23, 2026 | CVSS7.7v4.0 | EPSS3.62% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-12101MEDIUM | Cross-Site Scripting (XSS)Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | CVSS5.9v4.0 | EPSS25.4% | PoCs3 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2025-8424HIGH | Improper access control on the NetScaler Management InterfaceImproper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the appliance NSIP, Cluster Management IP or local GSLB Site IP or SNIP with Management Access CWE-1284Aug 26, 2025 | CVSS8.7v4.0 | EPSS2.82% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-7776HIGH | Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of ServiceMemory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it CWE-119Aug 26, 2025 | CVSS8.8v4.0 | EPSS6.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-7775CRITICAL | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of ServiceMemory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS an… CWE-119Aug 26, 2025 | CVSS9.2v4.0 | EPSS19.6% | PoCs5 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-6543CRITICAL | Memory overflow vulnerability leading to unintended control flow and Denial of ServiceMemory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server CWE-119Jun 25, 2025 | CVSS9.2v4.0 | EPSS10.1% | PoCs3 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-5349HIGH | NetScaler ADC and NetScaler Gateway - Improper access control on the NetScaler Management InterfaceImproper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway CWE-1284Jun 17, 2025 | CVSS8.7v4.0 | EPSS4.34% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-5777CRITICAL | NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overreadInsufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | CVSS9.3v4.0 | EPSS>99.9% | PoCs28 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2024-8535MEDIUM | Authenticated user can access unintended user capabilitiesAuthenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources OR the appliance must be configured as an Auth Server (AAA Vserver) with KCDAccount configuration for Kerberos SSO to access backend resources CWE-552Nov 12, 2024 | CVSS5.8v4.0 | EPSS0.422% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-8534HIGH | Memory safety vulnerability leading to memory corruption and Denial of ServiceMemory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway (VPN Vserver) OR the appliance must be configured as a Auth Server (AAA Vserver) with RDP Feature enabled | CVSS8.4v4.0 | EPSS0.562% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |