Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
| Vendor | Product | Versions |
|---|---|---|
| NetScaler | ADC | 14.1, 13.1, 13.1 FIPS and NDcPP, 12.1 FIPS and NDcPP |
| NetScaler | Gateway | 14.1, 13.1, 13.1 FIPS and NDcPP, 12.1 FIPS and NDcPP |
Yes — actively exploited. Added to the CISA KEV catalog on 2025-08-26. Ransomware use: Unknown.
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:
No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.