NetScaler (Citrix) Security Advisories & CVEs
8 advisories tracked · NetScaler / Cloud Software Group Security Bulletins · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor NetScaler CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Check if your NetScaler device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in NetScaler's recent advisories.
Official source
NetScaler / Cloud Software Group Security Bulletins
NetScaler CVE disclosures now live in Citrix Community Security Updates. VulniPulse polls the official Tech Zone RSS feed and keeps NetScaler-specific security-category bulletins and CTX guidance, including affected and fixed build details.
Latest NetScaler advisories
Critical [CVE-2026-107406] Protecting Customers: Immediate Guidance for CVE-2026-107406 in NetScaler ADC and NetScaler Gateway
Today, Citrix published a critical security bulletin for NetScaler ADC and NetScaler Gateway regarding CVE-2026-107406. CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial of service under specific configuration conditions. The issue carries a CVSS v4.0 base score of 9.5 and is rated Critical. We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible. As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability.
Critical [CVE-2026-88773] HTTP Request Smuggling
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
Critical [CVE-2026-88772] Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
Critical [CVE-2026-88771] A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
Critical [CVE-2026-19490] NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Critical [CVE-2025-7775 +2] Critical security update announced for NetScaler Gateway and NetScaler
Cloud Software Group released builds on August 26, 2025, to address three security vulnerabilities. NetScaler Gateway & NetScaler is affected by CVE-2025-7775, which has a CVSS score of 9.2. CVE-2025-7776 impacts NetScaler Gateway (CVSS 8.8), CVE-2025-8424 impacts NetScaler (CVSS 8.7). Affected products named by the advisory: NetScaler ADC; NetScaler Console.
Critical Leading the Quantum-Ready Transition: How NetScaler Helps Prevent a Silent Data Breach Decades in the Making
The Quantum Threat is No Longer Theoretical Today, every sensitive piece of data you create, transmit, and store is encrypted. The algorithms that have underpinned modern encryption standards have generally been viewed as robust and “unbreakable” —- but that foundation is about to collapse. Affected product named by the advisory: NetScaler Console.
Critical [CVE-2023-3519] NetScaler ADC: Unauthenticated remote code execution
Unauthenticated remote code execution Affected products named by the advisory: NetScaler ADC; NetScaler Gateway.