Citrix Netscaler Gateway vulnerabilities
29 known vulnerabilities affecting citrix/netscaler_gateway.
Total CVEs
29
CISA KEV
7
actively exploited
Public exploits
5
Exploited in wild
10
Severity breakdown
CRITICAL6HIGH19MEDIUM4
Vulnerabilities
Page 2 of 2
CVE-2026-13474P3HIGHCVSS 7.5≥ 13.1, < 13.1-63.18≥ 14.1, < 14.1-72.612026-06-30
CVE-2026-13474 [HIGH] CWE-401 CVE-2026-13474: Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is
Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
nvd
CVE-2020-8246P3HIGHCVSS 7.5≥ 12.1, < 12.1-58.152020-09-18
CVE-2020-8246 [HIGH] CWE-400 CVE-2020-8246: Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 1
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0
nvd
CVE-2021-22927P3HIGHCVSS 8.1≥ 11.1, < 11.1-65.222021-08-05
CVE-2021-22927 [HIGH] CWE-384 CVE-2021-22927: A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
nvd
CVE-2020-8300P3MEDIUMCVSS 6.5≥ 11.1, < 11.1-65.202021-06-16
CVE-2020-8300 [MEDIUM] CWE-284 CVE-2020-8300: Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to b
nvd
CVE-2021-22919P4HIGHCVSS 7.5≥ 11.1, < 11.1-65.222021-08-05
CVE-2021-22919 [HIGH] CWE-770 CVE-2021-22919: A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gatew
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the appliances being fully consumed.
nvd
CVE-2024-5491P4HIGHCVSS 7.5≥ 12.1, < 13.0-92.31≥ 13.1, < 13.1-53.17+1 more2024-07-10
CVE-2024-5491 [HIGH] CVE-2024-5491: Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler
Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler
nvd
CVE-2024-5492P4MEDIUMCVSS 6.1≥ 12.1, < 13.0-92.31≥ 13.1, < 13.1-53.17+1 more2024-07-10
CVE-2024-5492 [MEDIUM] CWE-601 CVE-2024-5492: Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary
Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway
nvd
CVE-2020-8245P4MEDIUMCVSS 6.1≥ 12.1, < 12.1-58.152020-09-18
CVE-2020-8245 [MEDIUM] CWE-79 CVE-2020-8245: Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and Ne
Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1
nvd
CVE-2020-8299P4MEDIUMCVSS 6.5≥ 11.1, < 11.1-65.202021-06-16
CVE-2020-8299 [MEDIUM] CWE-400 CVE-2020-8299: Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 1
Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from within the same Layer 2 network segmen
nvd
← Previous2 / 2