FAIL › dossier
NetScaler ADC and NetScaler Gateway
PRODUCT· dossier confidence 50%
NetScaler products have a history of critical vulnerabilities that have been actively exploited in the wild, linked to ransomware attacks.
PROFILE
CategoryNetwork SecurityWhat they doNetScaler ADC and NetScaler Gateway are load balancing and web application security products by Citrix.
SECURITY POSTURE
NetScaler products have a history of critical vulnerabilities that have been actively exploited in the wild.
Notable failures
- CVE-2023-4966: Critical buffer overflow vulnerability actively exploited in ransomware attacks
- CVE-2023-3519: Critical remote code execution vulnerability actively exploited in ransomware attacks
- CVE-2023-6548: High code injection vulnerability allowing authenticated remote code execution
- CVE-2023-6549: High buffer overflow vulnerability allowing denial-of-service
Patterns: Repeated critical vulnerabilities actively exploited in the wild; Linked to ransomware attacks
FAILURE HISTORY · 5
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-08-26 | CVE-2026-8452 | high | An unauthenticated attacker can execute arbitrary code as root on Citrix NetScaler ADC and Gateway appliances via CVE-2026-8452. |
| 2023-10-18 | CVE-2023-4966 | critical | Citrix NetScaler ADC and Gateway suffered a critical buffer overflow vulnerability that was actively exploited in the wild and linked to ransomware attacks. |
| 2023-07-19 | CVE-2023-3519 | critical | Citrix NetScaler ADC and Gateway suffered an unauthenticated remote code execution vulnerability that was actively exploited in the wild and linked to ransomware attacks. |
| 2024-01-17 | CVE-2023-6548 | high | Citrix NetScaler ADC/Gateway allows authenticated remote code execution on management interfaces via CVE-2023-6548, actively exploited in the wild. |
| 2024-01-17 | CVE-2023-6549 | high | Citrix NetScaler ADC/Gateway buffer overflow vulnerability (CVE-2023-6549) allows denial-of-service in VPN/AAA configurations and is actively exploited in the wild. |
Open questions: How has Citrix addressed these vulnerabilities? · What is Citrix's current security posture for NetScaler products?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-25 03:46:11.606922+00:00