CVE-2025-12101: NetScaler ADC

Medium severity, CVSS 5.9. EPSS: 25.4% chance of exploitation in the next 30 days.

Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Affected products

  • NetScaler ADC: from 14.1, before 56.73 (fixed in 56.73); from 13.1, before 60.32 (fixed in 60.32)
  • NetScaler Gateway: from 14.1, before 56.73 (fixed in 56.73); from 13.1, before 60.32 (fixed in 60.32)

Published 2025-11-11. Last modified 2026-06-17.