Wednesday, September 16, 2026
Follow on LinkedIn

Citrix NetScaler ADC and Gateway Vulnerabilities Allow Attackers to Access Sensitive Data

Two critical security vulnerabilities have been discovered in NetScaler ADC and NetScaler Gateway products, formerly known as Citrix ADC and Gateway, potentially allowing attackers to access sensitive data and compromise network security.

Cloud Software Group, the company behind these networking solutions, has issued an urgent security bulletin urging customers to immediately update their systems.

The vulnerabilities, identified as CVE-2025-5349 and CVE-2025-5777, carry critical severity ratings with CVSS scores of 8.7 and 9.3, respectively.

CVE-2025-5349 involves improper access control on the NetScaler Management Interface, while CVE-2025-5777 represents insufficient input validation leading to memory overread issues.

The first vulnerability requires access to the Network Services IP (NSIP), Cluster Management IP, or local Global Server Load Balancing (GSLB) Site IP to exploit.

The second, more severe vulnerability affects NetScaler systems configured as Gateway services, including VPN virtual servers, ICA Proxy, Citrix Virtual Private Network (CVPN), Remote Desktop Protocol (RDP) Proxy, or Authentication, Authorization, and Accounting (AAA) virtual servers.

Affected Versions

The security flaws affect numerous versions of NetScaler products currently in use by organizations worldwide. Vulnerable systems include NetScaler ADC and Gateway versions 14.1 before 14.1-43.56, version 13.1 before 13.1-58.32, and various FIPS-compliant versions.

Particularly concerning is that NetScaler versions 12.1 and 13.0, now designated as End of Life (EOL), remain vulnerable with no security patches available.

Organizations using Secure Private Access on-premises or hybrid deployments with NetScaler instances are also at risk and must upgrade their systems immediately. However, customers using Citrix-managed cloud services receive automatic updates from Cloud Software Group.

Cloud Software Group strongly recommends that affected customers install updated versions immediately. The company has released patched versions, including NetScaler ADC and Gateway 14.1-43.56, version 13.1-58.32, and corresponding FIPS-compliant updates.

Following the upgrade process, administrators should execute specific commands to terminate all active ICA and PCoIP sessions across all NetScaler appliances in high-availability pairs or clusters. This ensures complete protection against potential exploitation attempts.

The vulnerabilities were discovered through responsible disclosure by security researchers from Positive Technologies and ITA MOD CERT (CERTDIFESA), who worked collaboratively with Cloud Software Group to protect customers before public disclosure.

Organizations operating NetScaler infrastructure should prioritize these updates given the critical nature of these vulnerabilities and their potential for enabling unauthorized access to sensitive corporate data and network resources.

Live Credential Theft Attack Unmask & Instant Defense – Free Webinar

Guru Baran
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Cyber Security Guide

Latest Cyber News

Expert Talks