Known vulnerabilities in Citrix Netscaler ADC
Vendor:
Citrix
Software:
Citrix Netscaler ADC
Software CPE:
cpe:2.3:a:citrix:citrix_netscaler_adc:*:*:*:*:*:*:*:*
Website:
https://www.citrix.com/
Total vulnerabilities:
44
Public exploits:
10
Known exploited (KEV):
12
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
14.1-73.30
13.1-63.18
14.1-72.61
14.1-72.57
13.1-63.16
14.1-60.58
14.1-66.59
13.1-62.23
13.1-62.21
14.1-66.54
14.1-60.57
13.1-61.26
13.1-37.255
13.1-61.25
14.1-60.52
13.1-61.23
13.1-37.250
12.1-55.333
14.1-56.73
13.1-60.32
14.1-56.74
14.1-56.71
13.1-60.29
14.1-51.80
14.1-51.72
13.1-60.26
12.1-55.330
13.1-37.241
13.1-59.22
14.1-47.48
13.1-59.19
12.1-55.328
13.1-37.235
13.1-58.32
14.1-43.56
14.1-47.46
13.1-58.21
14.1-43.50
13.1-57.26
14.1-38.53
13.1-56.18
12.1-55.321
13.1-37.207
14.1-29.72
13.1-55.34
14.1-34.42
13.1-55.29
14.1-29.63
13.1-54.29
12.1-55.309
13.1-37.190
14.1-25.56
12.1-55.304
13.1-37.183
13.10-92.21
13.0-92.31
13.1-53.24
13.1-53.23
14.1-25.53
13.1-53.17
14.1-21.57
13.1-52.19
14.1-17.38
12.1-55.302
13.1-37.176
14.1-12.35
13.1-51.15
13.10-92.19
13.0-92.21
13.0-13.10
13.1-51.14
14.1-12.30
13.1-50.23
14.1-8.50
14.1-4.42
13.1-48.47
13.1-45.64
13.1-42.47
13.1-37.38
13.1-33.54
13.1-33.52
13.1-33.49
13.1-30.52
13.1-30
13.1-27.59
13.1-24.38
13.1-21.50
13.1-17.42
13.1-12.51
13.1-12.50
13.1-9.60
13.1-4.44
13.1-4.43
13.1-49.15
13.1-45.63
13.1-45.61
13.0-90.11
13.0-92.19
13.0-92.18
13.0-91.13
13.0-91.12
13.0-90.12
13.0-90.7
13.0-89.7
13.0-88.16
13.0-88.14
13.0-87.9
13.0-86.17
13.0-85.19
13.0-85.15
13.0-84.11
13.0-84.10
13.0-83.29
13.0-83.27
13.0-82.45
13.0-82.41
13.0-79.64
13.0-76.31
13.0-71.44
13.0-71.40
13.0-67.43
13.0-67.39
13.0-64.35
13.0-61.48
13.0-52.24
13.0-47.24
13.0-47.22
13.0-41.28
13.0-41.20
13.0-36.27
12.1-55.300
12.1-65.35
12.1-65.15
12.1-64.16
12.1-63.22
12.1-58.15
12.1-58.14
12.1-56.22
12.1-55.297
13.1-37.159
13.1-49.13
13.0.91.13
12.1-55.291
12.1-65.25
12.1-55.289
12.1-65.21
13.0-88.12
13.1-33.47
10.5 Build 70.18
11.1 Build 64.14
12.0 Build 63.21
13.0-58.32
13.0-58.30
12.1-57.18
12.1
12.0
12.0 Build 57.24
11.1 Build 58.13
11.0 Build 71.24
10.5 Build 68.7
10.5 Build 67.10/67.13
11.0 Build 71.18/71.22
11.1 Build 57.11/57.13
12.0 Build 56.20
11.0 Build 70.16
11.1 Build 55.13
12.0 Build 53.13
11.0 Build 70.12
11.1 Build 51.21
11.1 build 51.26
11.1 Build 52.13
11.1 build 53.11
11.1 build 54.14
11.1 build 54.16
11.1 build 55.10
12.0 build 41.16
12.0 build 41.22
12.0 Build 41.24
12.0 build 51.24
12.0 build 53.6
Vulnerabilities (44)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU135996 - Out-of-bounds read CVE-2026-8451 |
CWE-125 | Medium | 13.1-63.18, 14.1-72.61 | 30.06.2026 |
SB2026063084 |
||
| #VU135997 - Memory corruption CVE-2026-8452 |
CWE-119 | High | 13.1-63.18, 14.1-72.61 | 30.06.2026 |
SB2026063084 |
||
| #VU135998 - Memory corruption CVE-2026-8655 |
CWE-119 | Medium | 13.1-63.18, 14.1-72.61 | 30.06.2026 |
SB2026063084 |
||
| #VU135999 - External Control of File Name or Path CVE-2026-10816 |
CWE-73 | Low | 13.1-63.18, 14.1-72.61 | 30.06.2026 |
SB2026063084 |
||
| #VU136000 - Out-of-bounds read CVE-2026-10817 |
CWE-125 | Medium | 13.1-63.18, 14.1-72.61 | 30.06.2026 |
SB2026063084 |
||
| #VU136001 - Missing release of memory after effective lifetime CVE-2026-13474 |
CWE-401 | Medium | 13.1-63.18, 14.1-72.61 | 30.06.2026 |
SB2026063084 |
||
| #VU124257 - Out-of-bounds read CVE-2026-3055 |
CWE-125 | Critical | 13.1-62.23, 14.1-66.59 | 23.03.2026 |
SB2026032374 |
||
| #VU124256 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2026-4368 |
CWE-362 | Medium | 14.1-66.54 | 23.03.2026 |
SB2026032373 |
||
| #VU118307 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-12101 |
CWE-79 | Medium | 12.1-55.333, 13.1-37.250, 13.1-60.32, 14.1-56.73 | 11.11.2025 |
SB2025111173 |
||
| #VU114449 - Improper Access Control CVE-2025-8424 |
CWE-284 | Medium | 12.1-55.330, 13.1-37.241, 13.1-59.22, 14.1-47.48 | 27.08.2025 |
SB2025082719 |
||
| #VU114448 - Memory corruption CVE-2025-7776 |
CWE-119 | High | 12.1-55.330, 13.1-37.241, 13.1-59.22, 14.1-47.48 | 27.08.2025 |
SB2025082719 |
||
| #VU114447 - Memory corruption CVE-2025-7775 |
CWE-119 | Critical | 12.1-55.330, 13.1-37.241, 13.1-59.22, 14.1-47.48 | 27.08.2025 |
SB2025082719 |
||
| #VU111952 - Memory corruption CVE-2025-6543 |
CWE-119 | High | 13.1-59.19, 14.1-47.46 | 26.06.2025 |
SB2025062606 |
||
| #VU111237 - Out-of-bounds read CVE-2025-5777 |
CWE-125 | High | 12.1-55.328, 13.1-37.235, 13.1-58.32, 14.1-43.56 | 17.06.2025 |
SB2025061749 |
||
| #VU111236 - Improper Access Control CVE-2025-5349 |
CWE-284 | High | 12.1-55.328, 13.1-37.235, 13.1-58.32, 14.1-43.56 | 17.06.2025 |
SB2025061749 |
||
| #VU100415 - Improper Access Control CVE-2024-8535 |
CWE-284 | Medium | 12.1-55.321, 13.1-37.207, 13.1-55.34, 14.1-29.72 | 13.11.2024 |
SB2024111301 |
||
| #VU100414 - Memory corruption CVE-2024-8534 |
CWE-119 | Medium | 12.1-55.321, 13.1-37.207, 13.1-55.34, 14.1-29.72 | 13.11.2024 |
SB2024111301 |
||
| #VU94075 - Memory corruption CVE-2024-5491 |
CWE-119 | Low | 12.1-55.304, 13.0-92.31, 13.1-37.183, 13.1-53.17, 14.1-25.53 | 10.07.2024 |
SB2024071060 |
||
| #VU93515 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2006-5051 |
CWE-362 | Critical | 12.1-55.309, 13.0-92.31, 13.1-37.190, 13.1-53.24, 14.1-25.56 | 01.07.2024 |
SB2006092801 SB2024071109 SB2024071110 and 5 more |
||
| #VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2024-6387 |
CWE-362 | High | 12.1-55.309, 13.0-92.31, 13.1-37.190, 13.1-53.24, 14.1-25.56 | 01.07.2024 |
SB2024070144 SB2024070145 SB2024070152 and 89 more |
Showing elements 1 - 20 out of 44