Skip to content
VulniPulse

NetScaler (Citrix) Security Advisories & CVEs

8 advisories tracked · NetScaler / Cloud Software Group Security Bulletins · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor NetScaler CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Check if your NetScaler device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in NetScaler's recent advisories.

Official source

NetScaler / Cloud Software Group Security Bulletins

NetScaler CVE disclosures now live in Citrix Community Security Updates. VulniPulse polls the official Tech Zone RSS feed and keeps NetScaler-specific security-category bulletins and CTX guidance, including affected and fixed build details.

Latest NetScaler advisories

Critical9.5NetScaler Updated

Critical [CVE-2026-107406] Protecting Customers: Immediate Guidance for CVE-2026-107406 in NetScaler ADC and NetScaler Gateway

Today, Citrix published a critical security bulletin for NetScaler ADC and NetScaler Gateway regarding CVE-2026-107406. CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial of service under specific configuration conditions. The issue carries a CVSS v4.0 base score of 9.5 and is rated Critical. We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible. As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability.

CVE-2026-107406
NetScaler Gateway
Oct 8, 2026
Critical9.3NetScaler

Critical [CVE-2026-88773] HTTP Request Smuggling

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.

CVE-2026-88773
NetScaler Gateway
Sep 27, 2026
Critical9.5NetScaler Exploited CISA KEV

Critical [CVE-2026-88772] Memory overflow vulnerability leading to Remote Code Execution or Denial of Service

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

CVE-2026-88772
NetScaler Gateway
Sep 27, 2026
Critical9.5NetScaler Exploited CISA KEV

Critical [CVE-2026-88771] A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

CVE-2026-88771
NetScaler Gateway
Sep 27, 2026
Critical9.3NetScaler Exploited CISA KEV

Critical [CVE-2026-19490] NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

CVE-2026-19490
NetScaler Gateway
Aug 19, 2026
Critical9.2NetScaler Exploited CISA KEV

Critical [CVE-2025-7775 +2] Critical security update announced for NetScaler Gateway and NetScaler

Cloud Software Group released builds on August 26, 2025, to address three security vulnerabilities. NetScaler Gateway & NetScaler is affected by CVE-2025-7775, which has a CVSS score of 9.2. CVE-2025-7776 impacts NetScaler Gateway (CVSS 8.8), CVE-2025-8424 impacts NetScaler (CVSS 8.7). Affected products named by the advisory: NetScaler ADC; NetScaler Console.

CVE-2025-7775CVE-2025-7776CVE-2025-8424
NetScaler ADCNetScaler GatewayNetScaler Console
Aug 26, 2025
CriticalNetScaler

Critical Leading the Quantum-Ready Transition: How NetScaler Helps Prevent a Silent Data Breach Decades in the Making

The Quantum Threat is No Longer Theoretical Today, every sensitive piece of data you create, transmit, and store is encrypted. The algorithms that have underpinned modern encryption standards have generally been viewed as robust and “unbreakable” —- but that foundation is about to collapse. Affected product named by the advisory: NetScaler Console.

NetScaler Console
Jul 30, 2025
Critical9.8NetScaler Exploited CISA KEV

Critical [CVE-2023-3519] NetScaler ADC: Unauthenticated remote code execution

Unauthenticated remote code execution Affected products named by the advisory: NetScaler ADC; NetScaler Gateway.

CVE-2023-3519
NetScaler ADCNetScaler Gateway
Jul 19, 2023

← All vendors