CVE-2025-5349: Citrix NetScaler Application Delivery Controller
High severity, CVSS 8.8. EPSS: 6.2% chance of exploitation in the next 30 days.
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway
Affected products
- Citrix NetScaler Application Delivery Controller: from 12.1, before 12.1-55.328 (fixed in 12.1-55.328); from 13.1, before 13.1-37.235 (fixed in 13.1-37.235); from 13.1, before 13.1-58.32 (fixed in 13.1-58.32); from 14.1, before 14.1-43.56 (fixed in 14.1-43.56)
- Citrix NetScaler Gateway: from 13.1, before 13.1-58.32 (fixed in 13.1-58.32); from 14.1, before 14.1-43.56 (fixed in 14.1-43.56)
Published 2025-06-17. Last modified 2026-06-17.