PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2025-12101

5.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.
Description

Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Attack Vector
Network
Privileges Req.
None
User Interaction
A
adcgateway
Updated Sep 18, 2026View on NVD →
S4E scanner
mediumWeb Vulnerabilities~10 seconds

Citrix NetScaler ADC & Gateway - Reflected XSS

Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server. References: https://labs.watchtowr.com/is-it-citrixbleed4-well-no-is-it-good-also-no-citrix-netscalers-memory-leak-rxss-cve-2025-12101/?1

Used 2.8k times · domain, subdomain, ipv4

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →