Product of Citrix

NetScaler

As of , 6 Citrix NetScaler vulnerabilities are on CISA's list of exploited vulnerabilities; 5 were added in 2026. Patch first: CVE-2026-19490.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-19490Authentication Bypass Using an Alternate Path or ChannelCitrix NetScalerPatch nowForensic triage required by CISA0.23
2CVE-2026-88772Improper Restriction of Operations within the Bounds of a Memory BufferCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
3CVE-2026-88771Improper Input ValidationCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
4CVE-2026-88779Improper Restriction of Operations within the Bounds of a Memory BufferCitrix NetScalerPatch nowForensic triage required by CISA; listed in the last 14 days0.01
5CVE-2026-3055Out-of-Bounds ReadCitrix NetScalerPatch this weekMetasploit module0.04
6CVE-2025-7775Memory OverflowCitrix NetScalerPatch soon0.20

Added each year

2462025: 1120252026: 552026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20251
20265

Used in ransomware