NetScaler ADC is a technology platform tracked across 6 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed November 12, 2025; most recent activity July 3, 2026.
NetScaler ADC, today commonly known as Citrix ADC, is Citrix’s application delivery controller that provides load balancing, traffic management, and security features to ensure reliable delivery of enterprise apps. It is a high‑value, internet‑facing asset often targeted when Citrix products have security flaws, including zero-day vulnerabilities, making timely patching and monitoring critical for cybersecurity.
On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure and other products. The vulnerability allows unauthenticated remote code execution, and…
An advanced persistent threat actor exploited zero-day vulnerabilities in Cisco Identity Service Engine and Citrix NetScaler products. The attacks utilized custom malware and were detected by Amazon's MadPot honeypot…
Citrix disclosed six high-severity vulnerabilities in NetScaler ADC and Gateway appliances, including CVE-2026-8451, which allows unauthenticated memory disclosure when configured as a SAML identity provider. Other…
Cloud Software Group has identified and patched two critical vulnerabilities in Citrix NetScaler ADC and Gateway products. The vulnerabilities, tracked as CVE-2026-3055, allow unauthenticated remote attackers to exploit…
Two critical memory overflow vulnerabilities have been identified in NetScaler ADC and NetScaler Gateway, both published on July 2, 2026. CVE-2026-8655 affects configurations as an Oracle load balancer, DNS proxy, or…
An advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems, specifically CVE-2025-5777 and CVE-2025-20337. The attacks were detected by…