Netscaler Application Delivery Controller

Vendor:

First CVE: Oct 4, 2013 · Active for 12 years

38
Total CVEs
More Total CVEs than 97% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 69% of tracked products
21.1%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Netscaler Application Delivery Controller over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2013
12 years ago
Most Recent CVE
Jun 30, 2026
24 days ago

CVE Severity & Scoring

Netscaler Application Delivery Controller38 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network31 (81.6%)
Unknown5 (13.2%)
Physical0 (0.0%)
Adjacent Network2 (5.3%)
Attack Complexity
Low29 (76.3%)
High4 (10.5%)
Unknown5 (13.2%)
User Interaction
None29 (76.3%)
Unknown5 (13.2%)
Required4 (10.5%)
Privileges Required
Low2 (5.3%)
High0 (0.0%)
None31 (81.6%)
Unknown5 (13.2%)

Top CVEs

Signals from CVEs in this product scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
Mar 23, 20269.899YESYES
Unauthenticated remote code execution
Jul 19, 20239.899YESYES
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Jun 17, 20257.598YESYES
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.
Oct 10, 20237.598YESYES
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Rea
Jan 17, 20247.591YESYES
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual
Aug 26, 20259.883YESNO
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Pr
Jun 25, 20259.876YESNO
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to p
Jan 17, 20248.868YESNO
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured
Jun 30, 20269.844NONO
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (
Jun 30, 20269.844NONO

Exploit Exposure

Signals from CVEs in this product scope (38 CVEs).

CISA KEV
8 CVEs
21.1% of CVEs· 98th percentile
Metasploit
3 CVEs
7.9% of CVEs· 97th percentile
Nuclei
5 CVEs
13.2% of CVEs· 97th percentile
ExploitDB
1 CVE
2.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (38 CVEs).

Media Mentions

Signals from CVEs in this product scope (38 CVEs).

Top CNAs Publishing CVEs For Netscaler Application Delivery Controller

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
14.1-66.6868.30.4%00
12.017.52.9%00
11.1-65.2227.02.2%00
11.117.52.9%00
11.017.52.9%00