Documented CVEs
4 vulnerabilities cataloged in the Hermes intelligence repository.
| Parameter | Technical Specification |
|---|---|
| Official Name | Citrix NetScaler ADC & Gateway |
| Vendor / Project | citrix |
| Canonical ID | citrix:netscaler_adc |
| Versioning Scheme | semver |
| CPE Identifiers | cpe:2.3:a:citrix:netscaler_adc:*:*:*:*:*:*:*:*cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:* |
| Overall Posture | CRITICAL |
| Recommended Safe Release | 14.1-43.56 |
Documented CVEs
4 vulnerabilities cataloged in the Hermes intelligence repository.
CISA KEV Entries
4 flaws with confirmed active in-the-wild exploitation.
Weaponized Exploits
4 vulnerabilities with publicly available PoCs or weaponized exploit tooling.
Remediation Target
Recommended upgrade to 14.1-43.56 to neutralize known flaws.
Progression of Hermes Threat Score (HTS) posture and maximum EPSS probability over the last 30 days:
0 / 100
= Stable over 30d
100.0 %
= Stable over 30d
4
Active in-the-wild exploitation
| CVE | CVSS Score | EPSS Probability | CISA KEV | Affected Versions | Fixed In | Hermes Analysis |
|---|---|---|---|---|---|---|
| CVE-2026-8452 | 9.8 (CRITICAL) | 1.6% | CISA KEV | < v13.1-55.28, < v14.1-36.21 | 14.1-36.21, 13.1-55.28 | Analysis β |
| CVE-2026-19490 | 9.8 (CRITICAL) | 5.6% | CISA KEV | v13.1 to v13.1-53.17, v14.1 to v14.1-29.63 | 13.1-53.18, 14.1-29.64 | Analysis β |
| CVE-2025-5777 | 9.3 (CRITICAL) | 100.0% | CISA KEV | < v14.1-43.56, < v13.1-58.32, < v13.1-37.240, < v12.1-55.320 | 14.1-43.56, 13.1-58.32, 13.1-37.240, 12.1-55.320 | Analysis β |
| CVE-2026-3055 | 7.5 (HIGH) | 87.2% | CISA KEV | v13.1 to v13.1-53.17 | 13.1-53.18 | Analysis β |
Vulnerabilities impacting Citrix NetScaler ADC & Gateway are actively leveraged in real-world intrusion campaigns:
Are you operating Citrix NetScaler ADC & Gateway in your infrastructure? Inspect your running build to evaluate applicability, confidence score, and security deltas: