CVE-2018-6809: Citrix NetScaler Application Delivery Controller Firmware

Critical severity, CVSS 9.8. EPSS: 4.1% chance of exploitation in the next 30 days.

NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target system.

Affected products

  • Citrix NetScaler Application Delivery Controller Firmware: version 10.5 only; version 11.0 only; version 11.1 only; version 12.0 only
  • Citrix NetScaler Gateway Firmware: version 10.5 only; version 11.0 only; version 11.1 only; version 12.0 only

Published 2018-03-06. Last modified 2026-06-17.