VendorsCitrixnetscaler_application_delivery_controllerall versions
Vulnerabilities

Citrix Netscaler Application Delivery Controller

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

39CVEs
CVE-2018-6809
NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target system.
Published 2018-03-06 · Modified
10.0EPSS 0.041
CVE-2016-2071
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to gain privileges via unspecified NS Web GUI commands.
Published 2016-02-17 · Modified
10.0EPSS 0.034
CVE-2014-2881
Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI Java applet in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unknown impact and vectors.
Published 2014-05-01 · Modified
10.0EPSS 0.019
CVE-2014-2882
Unspecified vulnerability in the management GUI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unspecified impact and vectors, related to certificate validation.
Published 2014-05-01 · Modified
10.0EPSS 0.011
CVE-2023-3519
Unauthenticated remote code execution
Published 2023-07-19 · Analyzed
9.8KEVEPSS 0.997
CVE-2025-7775
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
Published 2025-08-26 · Analyzed
9.8KEVEPSS 0.196
CVE-2025-6543
Memory overflow vulnerability leading to unintended control flow and Denial of Service
Published 2025-06-25 · Analyzed
9.8KEVEPSS 0.101
CVE-2026-19490
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
Published 2026-08-19 · Analyzed
9.8KEVEPSS 0.070
CVE-2025-7776
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
Published 2025-08-26 · Analyzed
9.8EPSS 0.069
CVE-2026-3055
Insufficient input validation leading to memory overread
Published 2026-03-23 · Analyzed
9.8KEVEPSS 0.040
CVE-2026-8452
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
Published 2026-06-30 · Analyzed
9.8KEVEPSS 0.010
CVE-2026-8655
Multiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of Service
Published 2026-06-30 · Analyzed
9.8EPSS 0.006
CVE-2023-4966
Unauthenticated sensitive information disclosure
Published 2023-10-10 · Analyzed
9.4KEVEPSS 1.000
CVE-2025-5777
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
Published 2025-06-17 · Analyzed
9.3KEV1 PoCEPSS 1.000
CVE-2025-5349
NetScaler ADC and NetScaler Gateway - Improper access control on the NetScaler Management Interface
Published 2025-06-17 · Analyzed
8.8EPSS 0.062
CVE-2023-6548
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
Published 2024-01-17 · Analyzed
8.8KEVEPSS 0.032
CVE-2016-9028
Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header.
Published 2016-10-28 · Modified
8.8EPSS 0.018
CVE-2026-8451
Insufficient input validation leading to memory overread
Published 2026-06-30 · Analyzed
8.8EPSS 0.005
CVE-2026-13474
Denial of service via malformed HTTP/2 requests
Published 2026-06-30 · Analyzed
8.7EPSS 0.006
CVE-2024-8534
Memory safety vulnerability leading to memory corruption and Denial of Service
Published 2024-11-12 · Analyzed
8.4EPSS 0.006
CVE-2023-3466
Reflected Cross-Site Scripting (XSS)
Published 2023-07-19 · Modified
8.3EPSS 0.026
CVE-2023-6549
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
Published 2024-01-17 · Analyzed
8.2KEVEPSS 0.576
CVE-2023-4967
Denial of service
Published 2023-10-27 · Modified
8.2EPSS 0.009
CVE-2024-8535
Authenticated user can access unintended user capabilities
Published 2024-11-12 · Analyzed
8.1EPSS 0.004
CVE-2023-3467
Privilege Escalation to root administrator (nsroot)
Published 2023-07-19 · Modified
8.0EPSS 0.013
CVE-2013-6011
Citrix NetScaler Application Delivery Controller (ADC) 10.0 before 10.0-76.7 allows remote attackers to cause a denial of service (nsconfigd crash and appliance reboot) via a crafted request.
Published 2013-10-04 · Modified
7.8EPSS 0.015
CVE-2018-6810
Directory traversal vulnerability in NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allows remote attackers to traverse the directory on the target system via a crafted request.
Published 2018-03-06 · Modified
7.5EPSS 0.044
CVE-2018-5314
Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt.
Published 2018-03-01 · Modified
7.5EPSS 0.028
CVE-2018-6808
NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to download arbitrary files on the target system.
Published 2018-03-06 · Modified
7.5EPSS 0.023
CVE-2019-12044
A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23.
Published 2019-05-22 · Modified
7.5EPSS 0.015
CVE-2024-5491
Denial of Service
Published 2024-07-10 · Analyzed
7.5EPSS 0.008
CVE-2026-10816
Arbitrary File Read (Unauthenticated)
Published 2026-06-30 · Analyzed
7.5EPSS 0.006
CVE-2026-10817
Insufficient input validation leading to memory overread
Published 2026-06-30 · Analyzed
7.5EPSS 0.006
CVE-2016-2072
The Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, 10.5.e before Build 59.1305.e, and 10.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
Published 2016-02-17 · Modified
6.1EPSS 0.011
CVE-2024-5492
Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites
Published 2024-07-10 · Analyzed
6.1EPSS 0.006
CVE-2019-6485
Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 allow remote attackers to obtain sensitive plaintext information because of a TLS Padding Oracle Vulnerability when CBC-based cipher suites are enabled.
Published 2019-02-22 · Modified
5.9EPSS 0.023
CVE-2015-3642
The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x before 9.3 Build 68.5, 10.0 through Build 78.6, 10.1 before Build 130.13, 10.1.e before Build 130.1302.e, 10.5 before Build 55.8, and 10.5.e before Build 55.8007.e makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).
Published 2017-08-02 · Modified
5.9EPSS 0.008
CVE-2014-4347
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via vectors related to a cookie.
Published 2014-07-16 · Modified
5.0EPSS 0.017
CVE-2014-4346
Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2014-07-16 · Modified
4.3EPSS 0.017