Citrix NetScaler ADC and Gateway comprise Citrix's application delivery controller and secure remote-access platform, used by many enterprises for load balancing, application delivery, and VPN-style remote access.
Citrix NetScaler ADC and Gateway comprise Citrix's application delivery controller and secure remote-access platform, used by many enterprises for load balancing, application delivery, and VPN-style remote access. Recent reporting highlights a cross-site scripting vulnerability fixed by an update, underscoring the platform's exposure surface, and indicates that Citrix and Cisco 0-day exploits have been associated with advanced threat activity and weaponization.
An advanced persistent threat actor exploited zero-day vulnerabilities in Cisco Identity Service Engine and Citrix NetScaler products. The attacks utilized custom malware and were detected by Amazon's MadPot honeypot…
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
Citrix disclosed six high-severity vulnerabilities in NetScaler ADC and Gateway appliances, including CVE-2026-8451, which allows unauthenticated memory disclosure when configured as a SAML identity provider. Other…
The NCSC has issued an urgent advisory for UK organizations to address critical vulnerabilities affecting F5 BIG-IP Access Policy Manager, Citrix NetScaler ADC, and Citrix NetScaler Gateway. These vulnerabilities…
An advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems, specifically CVE-2025-5777 and CVE-2025-20337. The attacks were detected by…
A cross-site scripting (XSS) vulnerability has been identified in Citrix's NetScaler ADC and Gateway products, tracked as CVE-2025-12101. This flaw allows attackers to inject malicious scripts into web pages,…
A cross-site scripting (XSS) vulnerability has been identified in Citrix's NetScaler ADC and Gateway products, tracked as CVE-2025-12101. This flaw allows attackers to inject malicious scripts into web pages,…