Vulnerabilities in NetScaler

22 results
Vexday analysis

NetScaler apresenta 22 vulnerabilidades catalogadas, das quais 4 estão sob ataque ativo e 5 são críticas, indicando risco significativo de exploração. A fraqueza dominante é buffer overflow (CWE-119), classe historicamente severa e difícil de mitigar, com 6 novas descobertas nos últimos 90 dias sinalizando exposição contínua. Recomenda-se priorizar atualizações de segurança e monitoramento comportamental desta plataforma.

CVE-2025-5777CRITICALNetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overreadEPSS 100.0%KEVCVE-2026-3055CRITICALInsufficient input validation leading to memory overreadEPSS 84.5%KEVCVE-2025-12101MEDIUMCross-Site Scripting (XSS)EPSS 25.4%CVE-2024-6235CRITICALSensitive information disclosureEPSS 21.2%CVE-2025-7775CRITICALMemory overflow vulnerability leading to Remote Code Execution and/or Denial of ServiceEPSS 19.6%KEVCVE-2026-8451HIGHInsufficient input validation leading to memory overreadEPSS 15.7%CVE-2024-12284HIGHAuthenticated privilege escalationEPSS 13.4%CVE-2025-6543CRITICALMemory overflow vulnerability leading to unintended control flow and Denial of ServiceEPSS 10.1%KEVCVE-2025-4365MEDIUMNetScaler Console and NetScaler SDX (SVM) - Arbitrary file readEPSS 8.3%CVE-2025-7776HIGHMemory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of ServiceEPSS 6.9%CVE-2025-5349HIGHNetScaler ADC and NetScaler Gateway - Improper access control on the NetScaler Management InterfaceEPSS 4.3%CVE-2026-4368HIGHRace Condition leading to User Session MixupEPSS 3.6%CVE-2025-8424HIGHImproper access control on the NetScaler Management InterfaceEPSS 2.8%CVE-2024-5491HIGHDenial of ServiceEPSS 0.8%CVE-2024-6236HIGHDenial of ServiceEPSS 0.7%CVE-2024-8534HIGHMemory safety vulnerability leading to memory corruption and Denial of ServiceEPSS 0.6%CVE-2026-8655HIGHMultiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of ServiceEPSS 0.5%CVE-2026-8452HIGHMemory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of ServiceEPSS 0.5%CVE-2026-13474HIGHDenial of service via malformed HTTP/2 requestsEPSS 0.5%CVE-2024-8535MEDIUMAuthenticated user can access unintended user capabilitiesEPSS 0.4%