Skip to content
VulniPulse

NetScaler (Citrix) Security Advisories & CVEs

8 advisories tracked · NetScaler / Cloud Software Group Security Bulletins · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor NetScaler CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your NetScaler device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in NetScaler's recent advisories.

Official source

NetScaler / Cloud Software Group Security Bulletins

Polled via the official NetScaler blog RSS feed, filtered to security bulletin posts. Bulletin posts carry affected builds and link to the CTX security bulletin on Citrix Support (which sits behind a bot challenge and cannot be fetched directly).

Latest NetScaler advisories

Critical9.3NetScaler

Critical [CVE-2026-19490] NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

CVE-2026-19490
NetScaler Gateway
Aug 19, 2026
High8.8NetScaler

High [CVE-2026-19489] Vulnerability in NetScaler ADC and NetScaler Gateway

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

CVE-2026-19489
NetScaler Gateway
Aug 19, 2026
HighNetScaler Exploited CISA KEV

High [CVE-2026-3055] Important Update: CVE Disclosures Now Live on the Citrix Community Site

All CVE disclosure blogs have moved to The Citrix Community Site Going forward, all CVE disclosure blogs will be published in the Security Updates tab on the Citrix Community website. CVE-2026-3055 & CVE 2026-4368 Cloud Software Group released builds on March 23, 2026 to address CVE-2026-3055 and CVE 2026-4368.

CVE-2026-3055
Unclassified
Mar 27, 2026
Medium5.9NetScaler

Medium Medium severity security update announced for NetScaler Gateway and NetScaler

Cloud Software Group released builds on November 11, 2025, to address one security vulnerability. NetScaler Gateway & NetScaler is affected by CVE 2025-12101, which has a CVSS score of 5.9. CVE 2025-12101 is a cross-site scripting vulnerability impacting NetScaler Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy, or AAA virtual server). Affected products named by the advisory: NetScaler ADC.

NetScaler ADCNetScaler Gateway
Nov 11, 2025
Critical9.2NetScaler Exploited CISA KEV

Critical [CVE-2025-7775 +2] Critical security update announced for NetScaler Gateway and NetScaler

Cloud Software Group released builds on August 26, 2025, to address three security vulnerabilities. NetScaler Gateway & NetScaler is affected by CVE-2025-7775, which has a CVSS score of 9.2. CVE-2025-7776 impacts NetScaler Gateway (CVSS 8.8), CVE-2025-8424 impacts NetScaler (CVSS 8.7). Affected products named by the advisory: NetScaler ADC; NetScaler Console.

CVE-2025-7775CVE-2025-7776CVE-2025-8424
NetScaler ADCNetScaler GatewayNetScaler Console
Aug 26, 2025
CriticalNetScaler

Critical Leading the Quantum-Ready Transition: How NetScaler Helps Prevent a Silent Data Breach Decades in the Making

The Quantum Threat is No Longer Theoretical Today, every sensitive piece of data you create, transmit, and store is encrypted. The algorithms that have underpinned modern encryption standards have generally been viewed as robust and “unbreakable” —- but that foundation is about to collapse. Affected product named by the advisory: NetScaler Console.

NetScaler Console
Jul 30, 2025
UnratedNetScaler Exploited CISA KEV

Unknown [CVE-2025-5777] Evaluating NetScaler logs for indicators of attempted exploitation of CVE-2025-5777

In our recent update to our announcement of CVE 2025-5777, we noted that on July 10, 2025, CISA added CVE-2025-5777 to its Known Exploited Vulnerabilities Catalog. To help customers assess their security posture, we’ve provided additional guidance below. Affected product named by the advisory: Gateway.

CVE-2025-5777
NetScaler Gateway
Jul 16, 2025
Critical9.8NetScaler Exploited CISA KEV

Critical [CVE-2023-3519] NetScaler ADC: Unauthenticated remote code execution

Unauthenticated remote code execution Affected products named by the advisory: NetScaler ADC; NetScaler Gateway.

CVE-2023-3519
NetScaler ADCNetScaler Gateway
Jul 19, 2023

← All vendors