logo

Citrix NetScaler ADC and Gateway Vulnerability Enables Cross-Site Scripting Attacks

ID: b0f165ec-ff80-51c0-abae-ea5c90879e7d

STIX ID: report--b0f165ec-ff80-51c0-abae-ea5c90879e7d

Feed Name: cybersecurityNews.com

Threat Score
50/100

Date Published: 2025-11-12

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Citrix NetScaler ADC/Gateway XSS (CVE-2025-12101)**: Cloud Software Group disclosed a CWE-79 cross-site scripting vulnerability in NetScaler ADC and Gateway affecting multiple 12.x–14.x releases (including FIPS/NDcPP variants) that requires Gateway or AAA virtual-server configurations; the issue is assigned CVSSv4 5.9 (moderate), no active exploitation has been reported, and the vendor provides free patches and upgrade guidance while urging affected customers—especially those on EOL versions—to update or migrate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.