Product of Citrix
NetScaler
As of , 6 Citrix NetScaler vulnerabilities are on CISA's list of exploited vulnerabilities; 5 were added in 2026. Patch first: CVE-2026-19490.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-19490Authentication Bypass Using an Alternate Path or Channel | Citrix NetScaler | Patch nowForensic triage required by CISA | 0.23 | ||
| 2 | CVE-2026-88772Improper Restriction of Operations within the Bounds of a Memory Buffer | Citrix NetScaler | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 3 | CVE-2026-88771Improper Input Validation | Citrix NetScaler | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 4 | CVE-2026-88779Improper Restriction of Operations within the Bounds of a Memory Buffer | Citrix NetScaler | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 | ||
| 5 | CVE-2026-3055Out-of-Bounds Read | Citrix NetScaler | Patch this weekMetasploit module | 0.04 | ||
| 6 | CVE-2025-7775Memory Overflow | Citrix NetScaler | Patch soon | 0.20 |
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2025 | 1 |
| 2026 | 5 |