Citrix NetScaler Gateway — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
November 12, 2025
Last Seen
July 1, 2026

Citrix NetScaler ADC and Gateway comprise Citrix's application delivery controller and secure remote-access platform, used by many enterprises for load balancing, application delivery, and VPN-style remote access.

Overview

Citrix NetScaler ADC and Gateway comprise Citrix's application delivery controller and secure remote-access platform, used by many enterprises for load balancing, application delivery, and VPN-style remote access. Recent reporting highlights a cross-site scripting vulnerability fixed by an update, underscoring the platform's exposure surface, and indicates that Citrix and Cisco 0-day exploits have been associated with advanced threat activity and weaponization.

Related Threat Clusters

Recent Intelligence Reports

  • Multiple Citrix NetScaler ADC and Gateway Vulnerabilities Enables DoS and Memory Overflow Attacks — Cybersecuritynews · July 1, 2026
  • Attackers can disable Citrix NetScaler ADC and NetScaler Gateway — Heise.De · July 1, 2026
  • Log4Shell exploit — www.ncsc.gov.uk · April 15, 2026
  • Ivanti Connect Secure vulnerabilities — www.ncsc.gov.uk · April 15, 2026
  • Citrix Netscaler ADC and Gateway: Update closes cross-site scripting gap — Heise.De · November 13, 2025
  • Zero — Csoonline · November 13, 2025
  • Amazon: Cisco, Citrix 0-days indicate 'advanced' attacker — Theregister · November 12, 2025
  • Amazon: Cisco, Citrix 0-days indicate 'advanced' attacker — Theregister · November 12, 2025

CVSS v3.1 Breakdown