Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.
Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain.
Citrix Session Recording Deserialization of Untrusted Data Vulnerability
critical
activeCISA KEVCVE-2024-8069
Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server.
Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
critical
activeCISA KEVCVE-2025-5777
Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server. Known ransomware use: Known.
Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
critical
activeCISA KEVCVE-2025-6543
Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
critical
activeCISA KEVCVE-2023-6549
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
critical
activeCISA KEVCVE-2023-6548
Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
critical
activeCISA KEVCVE-2023-4966
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Known ransomware use: Known.
Citrix Content Collaboration ShareFile Improper Access Control Vulnerability
critical
activeCISA KEVCVE-2023-24489
Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers.
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
critical
activeCISA KEVCVE-2023-3519
Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution. Known ransomware use: Known.
Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability
critical
activeCISA KEVCVE-2022-27518
Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
netscaler application delivery controller
HIGHCVE-2026-8655
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 0.5% EPSS.
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
netscaler application delivery controller
HIGHCVE-2026-8452
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 0.5% EPSS.
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
netscaler application delivery controller
HIGHCVE-2026-8451
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 0.5% EPSS.
Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
netscaler application delivery controller
HIGHCVE-2026-13474
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 0.4% EPSS.
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
netscaler application delivery controller
MEDIUMCVE-2026-10817
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 0.4% EPSS.
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
netscaler application delivery controller
HIGHCVE-2026-10816
Watch
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 0.4% EPSS.
Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.
NetScaler
criticalCVE-2025-7775
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 19.0% EPSS.
Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain.
Session Recording
criticalCVE-2024-8068
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 1.4% EPSS.
Citrix Session Recording Deserialization of Untrusted Data Vulnerability
Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server.
Session Recording
criticalCVE-2024-8069
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 14.7% EPSS.
Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server. Known ransomware use: Known.
NetScaler ADC and Gateway
criticalCVE-2025-5777
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 99.9% EPSS.
Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.
NetScaler ADC and Gateway
criticalCVE-2025-6543
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 9.8% EPSS.
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
NetScaler ADC and NetScaler Gateway
criticalCVE-2023-6549
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 57.6% EPSS.
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.
NetScaler ADC and NetScaler Gateway
criticalCVE-2023-6548
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 3.2% EPSS.
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Known ransomware use: Known.
NetScaler ADC and NetScaler Gateway
criticalCVE-2023-4966
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 100.0% EPSS.
Citrix Content Collaboration ShareFile Improper Access Control Vulnerability
Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers.
Content Collaboration
criticalCVE-2023-24489
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 95.1% EPSS.
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution. Known ransomware use: Known.
NetScaler ADC and NetScaler Gateway
criticalCVE-2023-3519
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 99.7% EPSS.
Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability
Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.
Application Delivery Controller (ADC) and Gateway
criticalCVE-2022-27518
Critical
Priority score blends severity, KEV, recency, source signal, and EPSS where available. 6.9% EPSS.
The Citrixwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.
Confirm whether recent Citrix activity overlaps with your environment.
Prioritize advisories by MSP-relevance score, severity, and status.
Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.
At a glance
Tracked
47
Active
22
Featured
28
Unique CVEs
20
Most recent entry
Jun 30, 2026, 8:19 AM
Feed refreshes daily · 5:15 a.m. Central
Sources·CISA KEV and NVD (product vendor coverage)
"Most recent entry" is the newest item the upstream feed has published — not our sync time.
It is the Citrix-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.
How should teams use the Citrix watch page?
Use it to confirm whether current Citrix issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.
Can ITECS help respond to Citrix security issues?
Yes. ITECS can help map Citrix advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.