VendorsCitrixnetscaler_gatewayany version
Vulnerabilities

Citrix Netscaler Gateway any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2018-6809
NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target system.
Published 2018-03-06 · Modified
10.0EPSS 0.041
CVE-2016-2071
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to gain privileges via unspecified NS Web GUI commands.
Published 2016-02-17 · Modified
10.0EPSS 0.034
CVE-2019-19781
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
Published 2019-12-27 · Analyzed
9.8KEV3 PoCEPSS 1.000
CVE-2023-3519
Unauthenticated remote code execution
Published 2023-07-19 · Analyzed
9.8KEVEPSS 0.997
CVE-2025-7775
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
Published 2025-08-26 · Analyzed
9.8KEVEPSS 0.196
CVE-2025-6543
Memory overflow vulnerability leading to unintended control flow and Denial of Service
Published 2025-06-25 · Analyzed
9.8KEVEPSS 0.101
CVE-2026-19490
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
Published 2026-08-19 · Analyzed
9.8KEVEPSS 0.070
CVE-2025-7776
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
Published 2025-08-26 · Analyzed
9.8EPSS 0.069
CVE-2026-3055
Insufficient input validation leading to memory overread
Published 2026-03-23 · Analyzed
9.8KEVEPSS 0.040
CVE-2019-18225
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 before build 41.28. An attacker with management-interface access can bypass authentication to obtain appliance administrative access. These products formerly used the NetScaler brand name.
Published 2019-10-21 · Modified
9.8EPSS 0.015
CVE-2026-8452
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
Published 2026-06-30 · Analyzed
9.8KEVEPSS 0.010
CVE-2026-8655
Multiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of Service
Published 2026-06-30 · Analyzed
9.8EPSS 0.006
CVE-2023-4966
Unauthenticated sensitive information disclosure
Published 2023-10-10 · Analyzed
9.4KEVEPSS 1.000
CVE-2025-5777
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
Published 2025-06-17 · Analyzed
9.3KEV1 PoCEPSS 1.000
CVE-2017-7219
A heap overflow vulnerability in Citrix NetScaler Gateway versions 10.1 before 135.8/135.12, 10.5 before 65.11, 11.0 before 70.12, and 11.1 before 52.13 allows a remote authenticated attacker to run arbitrary commands via unspecified vectors.
Published 2017-04-13 · Modified
9.0EPSS 0.049
CVE-2025-5349
NetScaler ADC and NetScaler Gateway - Improper access control on the NetScaler Management Interface
Published 2025-06-17 · Analyzed
8.8EPSS 0.062
CVE-2023-6548
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
Published 2024-01-17 · Analyzed
8.8KEVEPSS 0.032
CVE-2020-8197
Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary commands.
Published 2020-07-10 · Modified
8.8EPSS 0.018
CVE-2020-8247
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b are vulnerable to escalation of privileges on the management interface.
Published 2020-09-18 · Modified
8.8EPSS 0.014
CVE-2026-8451
Insufficient input validation leading to memory overread
Published 2026-06-30 · Analyzed
8.8EPSS 0.005
CVE-2026-13474
Denial of service via malformed HTTP/2 requests
Published 2026-06-30 · Analyzed
8.7EPSS 0.006
CVE-2024-8534
Memory safety vulnerability leading to memory corruption and Denial of Service
Published 2024-11-12 · Analyzed
8.4EPSS 0.006
CVE-2023-3466
Reflected Cross-Site Scripting (XSS)
Published 2023-07-19 · Modified
8.3EPSS 0.026
CVE-2023-6549
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
Published 2024-01-17 · Analyzed
8.2KEVEPSS 0.576
CVE-2023-4967
Denial of service
Published 2023-10-27 · Modified
8.2EPSS 0.009
CVE-2021-22927
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
Published 2021-08-05 · Modified
8.1EPSS 0.008
CVE-2024-8535
Authenticated user can access unintended user capabilities
Published 2024-11-12 · Analyzed
8.1EPSS 0.004
CVE-2023-3467
Privilege Escalation to root administrator (nsroot)
Published 2023-07-19 · Modified
8.0EPSS 0.013
CVE-2018-6810
Directory traversal vulnerability in NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allows remote attackers to traverse the directory on the target system via a crafted request.
Published 2018-03-06 · Modified
7.5EPSS 0.044
CVE-2018-6808
NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to download arbitrary files on the target system.
Published 2018-03-06 · Modified
7.5EPSS 0.023
CVE-2020-8187
Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticated users to perform a denial of service attack.
Published 2020-07-10 · Modified
7.5EPSS 0.019
CVE-2020-8246
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b are vulnerable to a denial of service attack originating from the management network.
Published 2020-09-18 · Modified
7.5EPSS 0.016
CVE-2019-12044
A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23.
Published 2019-05-22 · Modified
7.5EPSS 0.015
CVE-2020-8190
Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation.
Published 2020-07-10 · Modified
7.5EPSS 0.012
CVE-2021-22919
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the appliances being fully consumed.
Published 2021-08-05 · Modified
7.5EPSS 0.009
CVE-2024-5491
Denial of Service
Published 2024-07-10 · Analyzed
7.5EPSS 0.008
CVE-2026-10816
Arbitrary File Read (Unauthenticated)
Published 2026-06-30 · Analyzed
7.5EPSS 0.006
CVE-2026-10817
Insufficient input validation leading to memory overread
Published 2026-06-30 · Analyzed
7.5EPSS 0.006
CVE-2020-8194
Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download.
Published 2020-07-10 · Modified
6.5EPSS 0.107
CVE-2020-8300
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to be possible.
Published 2021-06-16 · Modified
6.5EPSS 0.030
1 / 2Next →