NetScaler Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for NetScaler products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
6
In CISA KEV
4
Beyond CISA KEV
2
Sensor Observed
3
Virtual Patch Available
0
NetScaler KEVs Added by Year
6 NetScaler KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-8451
Insufficient input validation leading to memory overread |
ADC, Gateway | Confirmed | Not in CISA | 01 Jul 2026 |
|
CVE-2024-6235
Sensitive information disclosure |
NetScaler Console | High | Not in CISA | 11 Nov 2025 |
|
CVE-2026-3055
Insufficient input validation leading to memory overread |
ADC, Gateway | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-7775
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service |
ADC, Gateway | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-5777
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread |
ADC, Gateway | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-6543
Memory overflow vulnerability leading to unintended control flow and Denial of Service |
ADC, Gateway | Confirmed | In CISA | 01 Jun 2026 |
Common Vulnerability Classes (CWE)
- CWE-125 — Out-of-bounds Read 3
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 2
- CWE-287 — Improper Authentication 1
- CWE-457 — Use of Uninitialized Variable 1
- CWE-908 — Use of Uninitialized Resource 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology