Product of Citrix

NetScaler ADC and NetScaler Gateway

As of , 5 Citrix NetScaler ADC and NetScaler Gateway vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 1 was added in 2026. Patch first: CVE-2023-4966.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2023-4966Buffer OverflowCitrix NetScaler ADC and NetScaler GatewayPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
2CVE-2023-3519Code InjectionCitrix NetScaler ADC and NetScaler GatewayPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
3CVE-2023-6549Buffer OverflowCitrix NetScaler ADC and NetScaler GatewayPatch this weekEPSS 0.580.58
4CVE-2023-6548Code InjectionCitrix NetScaler ADC and NetScaler GatewayPatch soon0.03
5CVE-2026-8452Improper Restriction of Operations within the Bounds of a Memory BufferCitrix NetScaler ADC and NetScaler GatewayPatch soon0.01

Added each year

0.511.522023: 2220232024: 2220242025: nonenone20252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20232
20242
2025none
20261

Used in ransomware