Skip to content
Citrix NetScaler ADC and Gateway XSS Vulnerability Disclosed

Citrix NetScaler ADC and Gateway XSS Vulnerability Disclosed

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A cross-site scripting (XSS) vulnerability has been identified in Citrix's NetScaler ADC and Gateway products, tracked as CVE-2025-12101. This flaw allows attackers to inject malicious scripts into web pages, potentially leading to session hijacking and data theft. A software update has been released to address the vulnerability, and administrators are advised to implement it promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 197d ago How this analysis works

More articles in this cluster (4)

Following this threat?

Track Citrix and CVE-2025-12101 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed