Skip to content

Products › Network and edge

Network and edge

Load balancers and access gateways (ADC)

Appliances placed in front of applications to balance load, filter web traffic or publish remote access.

For example: Citrix NetScaler, F5 BIG-IP, FortiWeb, Kemp LoadMaster.

Category RSS feed

Pace of additions

Number of “ADCs” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on October 3, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 9, 2025 to Oct 8, 20250
Oct 9, 2025 to Nov 7, 20250
Nov 8, 2025 to Dec 7, 20252
Dec 8, 2025 to Jan 6, 20260
Jan 7, 2026 to Feb 5, 20260
Feb 6, 2026 to Mar 7, 20260
Mar 8, 2026 to Apr 6, 20262
Apr 7, 2026 to May 6, 20260
May 7, 2026 to Jun 5, 20260
Jun 6, 2026 to Jul 5, 20260
Jul 6, 2026 to Aug 4, 20260
Aug 5, 2026 to Sep 3, 20262
Sep 4, 2026 to Oct 3, 2026 (in progress)4

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

  • Citrix 17 vulnerabilities · 5 in the last 12 months
  • F5 8 vulnerabilities · 2 in the last 12 months
  • Fortinet 3 vulnerabilities · 2 in the last 12 months
  • Ivanti 1 vulnerability
  • Progress 2 vulnerabilities · 1 in the last 12 months

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1

    Citrix NetScaler ADC / GatewayCVE-2026-88771

    Citrix NetScaler Improper Input Validation Vulnerability

    Recently addedActive CERT-FR alertHunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Sep 27, 2026

  2. Rank 2

    Citrix NetScaler ADC / GatewayCVE-2026-88772

    Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Recently addedActive CERT-FR alertHunt for compromise (CISA)

    CVSS severity 8.1high

    Added Sep 27, 2026

  3. Rank 3

    F5 BIG-IPCVE-2026-94127

    F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

    Recently addedHunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Sep 22, 2026

  4. Rank 4

    Citrix NetScaler ADC / GatewayCVE-2026-19490

    Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Recently addedHunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Sep 9, 2026

  5. Rank 5

    Citrix NetScaler ADC / GatewayCVE-2026-8452

    Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    CVSS severity 9.8critical

    Added Aug 26, 2026

  6. Rank 6

    Progress Kemp LoadMasterCVE-2026-8037

    Progress LoadMaster Command Injection Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Aug 7, 2026

  7. Rank 7

    Citrix NetScaler ADC / GatewayCVE-2026-3055

    Citrix NetScaler Out-of-Bounds Read Vulnerability

    CVSS severity 9.8critical

    Added Mar 30, 2026

  8. Rank 8

    F5 BIG-IPCVE-2025-53521

    F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

    CVSS severity 9.8critical

    Added Mar 27, 2026

  9. Rank 9

    Fortinet FortiWebCVE-2025-64446

    Fortinet FortiWeb Path Traversal Vulnerability

    CVSS severity 9.8critical

    Added Nov 14, 2025

  10. Rank 10

    Fortinet FortiWebCVE-2025-58034

    Fortinet FortiWeb OS Command Injection Vulnerability

    CVSS severity 7.2high

    Added Nov 18, 2025

Show 21 more vulnerabilities
  1. Rank 11

    Citrix NetScaler ADC / GatewayCVE-2025-7775

    Citrix NetScaler Memory Overflow Vulnerability

    CVSS severity 9.8critical

    Added Aug 26, 2025

  2. Rank 12

    Fortinet FortiWebCVE-2025-25257

    Fortinet FortiWeb SQL Injection Vulnerability

    CVSS severity 9.8critical

    Added Jul 18, 2025

  3. Rank 13

    Citrix NetScaler ADC / GatewayCVE-2025-6543

    Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability

    CVSS severity 9.8critical

    Added Jun 30, 2025

  4. Rank 14

    Progress Kemp LoadMasterCVE-2024-1212

    Progress Kemp LoadMaster OS Command Injection Vulnerability

    CVSS severity 9.8critical

    Added Nov 18, 2024

  5. Rank 15

    Ivanti Virtual Traffic Manager (vTM)CVE-2024-7593

    Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability

    CVSS severity 9.8critical

    Added Sep 24, 2024

  6. Rank 16

    F5 BIG-IPCVE-2023-46747

    F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Oct 31, 2023

  7. Rank 17

    Citrix NetScaler ADC / GatewayCVE-2023-3519

    Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jul 19, 2023

  8. Rank 18

    Citrix NetScaler ADC / GatewayCVE-2022-27518

    Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

    CVSS severity 9.8critical

    Added Dec 13, 2022

  9. Rank 19

    F5 BIG-IPCVE-2022-1388

    F5 BIG-IP Missing Authentication Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added May 10, 2022

  10. Rank 20

    F5 BIG-IPCVE-2021-22991

    F5 BIG-IP Traffic Management Microkernel Buffer Overflow

    CVSS severity 9.8critical

    Added Jan 18, 2022

  11. Rank 21

    Citrix NetScaler ADC / GatewayCVE-2019-19781

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

    RansomwareCVE from 2019, added in 2021

    CVSS severity 9.8critical

    Added Nov 3, 2021

  12. Rank 22

    F5 BIG-IPCVE-2020-5902

    F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Nov 3, 2021

  13. Rank 23

    F5 BIG-IPCVE-2021-22986

    F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Nov 3, 2021

  14. Rank 24

    Citrix NetScaler ADC / GatewayCVE-2023-6548

    Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

    CVSS severity 8.8high

    Added Jan 17, 2024

  15. Rank 25

    F5 BIG-IPCVE-2023-46748

    F5 BIG-IP Configuration Utility SQL Injection Vulnerability

    CVSS severity 8.8high

    Added Oct 31, 2023

  16. Rank 26

    Citrix NetScaler ADC / GatewayCVE-2025-5777

    Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

    Ransomware

    CVSS severity 7.5high

    Added Jul 10, 2025

  17. Rank 27

    Citrix NetScaler ADC / GatewayCVE-2023-6549

    Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

    CVSS severity 7.5high

    Added Jan 17, 2024

  18. Rank 28

    Citrix NetScaler ADC / GatewayCVE-2023-4966

    Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

    Ransomware

    CVSS severity 7.5high

    Added Oct 18, 2023

  19. Rank 29

    Citrix NetScaler ADC / GatewayCVE-2020-8193

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability

    CVSS severity 6.5medium

    Added Nov 3, 2021

  20. Rank 30

    Citrix NetScaler ADC / GatewayCVE-2020-8195

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

    CVSS severity 6.5medium

    Added Nov 3, 2021

  21. Rank 31

    Citrix NetScaler ADC / GatewayCVE-2020-8196

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

    CVSS severity 4.3medium

    Added Nov 3, 2021

Filed under another category

These 3 vulnerabilities also concern this type of product, but are counted in their main category. My radar finds them when you follow this category.

  1. Fortinet FortiOS / FortiProxy (FortiGate)CVE-2025-59718

    Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

    CVSS severity 9.8critical

    Added Dec 16, 2025

  2. Fortinet FortiOS / FortiProxy (FortiGate)CVE-2024-23113

    Fortinet Multiple Products Format String Vulnerability

    CVSS severity 9.8critical

    Added Oct 9, 2024

  3. Fortinet FortiOS / FortiProxy (FortiGate)CVE-2018-13374

    Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

    RansomwareCVE from 2018, added in 2022

    CVSS severity 4.3medium

    Added Sep 8, 2022

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.