Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
Citrix · NetScaler ADC and Gateway
Date added (CISA)
2025-06-30
Remediation due
2025-07-21
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.