NetScaler
First CVE: Mar 23, 2026Active for: 1 year
8
CVEs Published
More CVEs Published than 22% of tracked CNAs
8.0
Avg CVEs / Year
More Avg CVEs / Year than 47% of tracked CNAs
8.4
Avg CVSS Score
Higher Avg CVSS Score than 92% of tracked CNAs
12.5%
In CISA KEV
Higher KEV Rate than 99% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by NetScaler over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 23, 2026
4 months ago
Most Recent CVE
Jun 30, 2026
25 days ago
Top CVEs
All CVEs published by NetScaler as a CNA, regardless of affected vendor or product.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3055CRITICAL Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread | Mar 23, 2026 | 9.8 | 98 | YES | YES |
CVE-2026-8451HIGH Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP | Jun 30, 2026 | 7.5 | 52 | NO | NO |
CVE-2026-8655CRITICAL Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured | Jun 30, 2026 | 9.8 | 44 | NO | NO |
CVE-2026-8452CRITICAL Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway ( | Jun 30, 2026 | 9.8 | 44 | NO | NO |
CVE-2026-13474HIGH Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, | Jun 30, 2026 | 7.5 | 37 | NO | NO |
CVE-2026-10817HIGH Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual se | Jun 30, 2026 | 7.5 | 37 | NO | NO |
CVE-2026-10816HIGH Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled | Jun 30, 2026 | 7.5 | 37 | NO | NO |
CVE-2026-4368HIGH Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mi | Mar 23, 2026 | 7.7 | 35 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA8 CVEs
63%
38%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None7 (87.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (8 CVEs).
CISA KEV
1 CVE
12.5% of CVEs· 99th percentile
Metasploit
1 CVE
12.5% of CVEs· 99th percentile
Nuclei
1 CVE
12.5% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by NetScaler as a CNA.
Media Mentions
Media articles that mention a CVE ID published by NetScaler as a CNA — matched by CVE ID, not by organization name.