Improper access control in Citrix Netscaler ADC and Citrix NetScaler Gateway - CVE-2025-8424
Published: August 27, 2025 / Updated: August 30, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the NetScaler Management Interface. A remote attacker on the local network can bypass implemented security restrictions and gain unauthorized access to the application.
Affected software
Citrix NetScaler Gateway
How to mitigate CVE-2025-8424
Citrix NetScaler Gateway - addressed in versions 13.1-59.22, 14.1-47.48