Vulnerabilities (CVE)

Filtered by vendor Citrix Subscribe
Total 457 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-3519 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2026-08-05 N/A 9.8 CRITICAL
Unauthenticated remote code execution
CVE-2025-5777 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2026-08-04 N/A 7.5 HIGH
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CVE-2023-4966 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2026-07-31 N/A 9.4 CRITICAL
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.
CVE-2026-10816 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2026-07-02 N/A 7.5 HIGH
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
CVE-2026-10817 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2026-07-02 N/A 7.5 HIGH
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
CVE-2026-13474 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2026-07-02 N/A 7.5 HIGH
Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
CVE-2026-8451 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2026-07-01 N/A 7.5 HIGH
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
CVE-2026-8452 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2026-07-01 N/A 9.8 CRITICAL
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
CVE-2026-8655 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2026-07-01 N/A 9.8 CRITICAL
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
CVE-2026-3055 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2026-06-17 N/A 9.8 CRITICAL
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
CVE-2025-7776 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2026-06-17 N/A 9.8 CRITICAL
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it
CVE-2025-7775 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2026-06-17 N/A 9.8 CRITICAL
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers (OR) CR virtual server with type HDX
CVE-2025-6759 1 Citrix 1 Virtual Apps And Desktops 2026-06-17 N/A 7.8 HIGH
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS
CVE-2025-6543 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2026-06-17 N/A 9.8 CRITICAL
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CVE-2025-5349 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2026-06-17 N/A 8.8 HIGH
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway
CVE-2025-4879 1 Citrix 1 Workspace 2026-06-17 N/A 7.8 HIGH
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
CVE-2025-4365 1 Citrix 2 Netscaler Console, Netscaler Sdx 2026-06-17 N/A 7.5 HIGH
Arbitrary file read in NetScaler Console and NetScaler SDX (SVM)
CVE-2025-1223 2 Apple, Citrix 2 Macos, Secure Access Client 2026-06-17 N/A 6.1 MEDIUM
An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac
CVE-2025-1222 2 Apple, Citrix 2 Macos, Secure Access Client 2026-06-17 N/A 6.1 MEDIUM
An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac
CVE-2025-0320 2 Citrix, Microsoft 2 Secure Access Client, Windows 2026-06-17 N/A 7.8 HIGH
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows