NetScaler

First CVE: Mar 23, 2026Active for: 1 year
8
CVEs Published
More CVEs Published than 22% of tracked CNAs
8.0
Avg CVEs / Year
More Avg CVEs / Year than 47% of tracked CNAs
8.4
Avg CVSS Score
Higher Avg CVSS Score than 92% of tracked CNAs
12.5%
In CISA KEV
Higher KEV Rate than 99% of tracked CNAs

Trends Over Time

The number and severity of CVEs published by NetScaler over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 23, 2026
4 months ago
Most Recent CVE
Jun 30, 2026
25 days ago

Top CVEs

All CVEs published by NetScaler as a CNA, regardless of affected vendor or product.

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
Mar 23, 20269.898YESYES
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
Jun 30, 20267.552NONO
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured
Jun 30, 20269.844NONO
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (
Jun 30, 20269.844NONO
Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS,
Jun 30, 20267.537NONO
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual se
Jun 30, 20267.537NONO
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
Jun 30, 20267.537NONO
Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mi
Mar 23, 20267.735NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA8 CVEs
Severity distribution among all CVEs352,427 CVEs
HighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None7 (87.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (8 CVEs).

CISA KEV
1 CVE
12.5% of CVEs· 99th percentile
Metasploit
1 CVE
12.5% of CVEs· 99th percentile
Nuclei
1 CVE
12.5% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by NetScaler as a CNA.

Media Mentions

Media articles that mention a CVE ID published by NetScaler as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs