NetScaler vendor intelligence
NetScaler Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting NetScaler products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 11
- Known exploited vulnerabilities affecting NetScaler products
- In CISA KEV
- 9
- Records also listed in the official catalog
- Beyond CISA KEV
- 2
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 7
- NetScaler KEVs with sensor-observed exploitation activity
The catalog gap matters for NetScaler exposure
Two of the eleven exploited NetScaler vulnerabilities tracked by Previdian are not in CISA KEV. Teams relying on the official catalog alone would miss 18% of this vendor portfolio.
- 82%
- Covered by CISA
- 18%
- Beyond CISA
- 2
- Product families
Attested NetScaler vulnerabilities
11 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-88779
Memory overflow vulnerability leading to Denial of Service |
ADC, Gateway | Confirmed | In CISA | 04 Oct 2026 |
|
CVE-2026-88772
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service |
ADC, Gateway | Confirmed | In CISA | 27 Sep 2026 |
|
CVE-2026-88771
A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands |
ADC, Gateway | Confirmed | In CISA | 27 Sep 2026 |
|
CVE-2026-19490
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 |
ADC, Gateway | Confirmed | In CISA | 03 Sep 2026 |
|
CVE-2026-8452
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service |
ADC, Gateway | Confirmed | In CISA | 17 Aug 2026 |
|
CVE-2026-8451
Insufficient input validation leading to memory overread |
ADC, Gateway | Confirmed | Beyond CISA | 01 Jul 2026 |
|
CVE-2024-6235
Sensitive information disclosure |
NetScaler Console | High | Beyond CISA | 11 Nov 2025 |
|
CVE-2026-3055
Insufficient input validation leading to memory overread |
ADC, Gateway | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-7775
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service |
ADC, Gateway | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-5777
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread |
ADC, Gateway | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-6543
Memory overflow vulnerability leading to unintended control flow and Denial of Service |
ADC, Gateway | Confirmed | In CISA | 01 Jun 2026 |
No NetScaler vulnerabilities match this search or filter.
Showing 11 of 11 on this page (11 NetScaler known exploited vulnerabilities).
Recurring weakness patterns
Restriction, out-of-bounds read, and input validation account for nine mapped occurrences across this NetScaler KEV portfolio.