NetScaler (Citrix) NetScaler ADC Vulnerabilities & Security Advisories
4 advisories tracked · NetScaler / Cloud Software Group Security Bulletins · 3 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published NetScaler (Citrix) advisory that VulniPulse classified as NetScaler ADC, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 2 critical, 1 medium.
Android app · Google Play
Monitor NetScaler CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Source
NetScaler / Cloud Software Group Security Bulletins
NetScaler CVE disclosures now live in Citrix Community Security Updates. VulniPulse polls the official Tech Zone RSS feed and keeps NetScaler-specific security-category bulletins and CTX guidance, including affected and fixed build details.
Latest NetScaler NetScaler ADC advisories
Advisory [CVE-2026-88771 +7] Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
Guidance for customers on newly addressed vulnerabilities and recommended updates As the cybersecurity landscape continues to evolve, organizations across the industry are seeing changes in the pace, scale, and complexity of vulnerability research, discovery, and analysis. AI-assisted research and automation may contribute to this shift by enabling faster identification and validation of certain classes of security issues. Citrix continues to invest in secure development, security testing, coordinated disclosure, and vulnerability response processes. Citrix has released updates for NetScaler ADC and NetScaler Gateway to address multiple security vulnerabilities. These vulnerabilities vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions. Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. Citrix strongly urges affected customers to install the relevant updated versions as soon as possible. Summary of Vulnerabilities CVE ID Description Preconditions CWE CVSS v4.0 CVE-2026-88771 Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
Medium Medium severity security update announced for NetScaler Gateway and NetScaler
Cloud Software Group released builds on November 11, 2025, to address one security vulnerability. NetScaler Gateway & NetScaler is affected by CVE 2025-12101, which has a CVSS score of 5.9. CVE 2025-12101 is a cross-site scripting vulnerability impacting NetScaler Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy, or AAA virtual server). Affected products named by the advisory: NetScaler ADC.
Critical [CVE-2025-7775 +2] Critical security update announced for NetScaler Gateway and NetScaler
Cloud Software Group released builds on August 26, 2025, to address three security vulnerabilities. NetScaler Gateway & NetScaler is affected by CVE-2025-7775, which has a CVSS score of 9.2. CVE-2025-7776 impacts NetScaler Gateway (CVSS 8.8), CVE-2025-8424 impacts NetScaler (CVSS 8.7). Affected products named by the advisory: NetScaler ADC; NetScaler Console.
Critical [CVE-2023-3519] NetScaler ADC: Unauthenticated remote code execution
Unauthenticated remote code execution Affected products named by the advisory: NetScaler ADC; NetScaler Gateway.