Executive brief
Citrix NetScaler ADC and Gateway, which are used to provide secure remote access and load balancing for corporate applications, are affected by a critical security flaw. An attacker can exploit this vulnerability to disrupt services or potentially gain unauthorized control over the device. This issue is particularly serious as it is known to be actively exploited in the wild, potentially allowing attackers to bypass security controls or crash the gateway.
Technical details
A memory buffer overflow vulnerability (CWE-119) exists in Citrix NetScaler ADC and Gateway. The flaw is triggered when the device is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. A remote, unauthenticated attacker can exploit this over the network to cause a denial-of-service (DoS) condition or achieve unintended control flow, potentially leading to remote code execution. The vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Patches are available in versions 13.1-59.19, 14.1-47.46, and related maintenance releases.
Affected products
- Citrix NetScaler ADC 13.1 before 13.1-59.19, 13.1 FIPS before 13.1-37.236, 14.1 before 14.1-47.46
- Citrix NetScaler Gateway 13.1 before 13.1-59.19, 14.1 before 14.1-47.46
Timeline
- 2025-06-25: disclosed: Initial disclosure by Citrix
- 2025-06-30: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-06-30: advisory: NVD publication date