Skip to content
English

Products › Network and edge

Network and edge

Load balancers and access gateways (ADC)

Appliances placed in front of applications to balance load, filter web traffic or publish remote access.

For example: Citrix NetScaler, F5 BIG-IP, FortiWeb, Kemp LoadMaster.

Category RSS feed

Pace of additions

Number of “ADCs” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20250
Oct 4, 2025 to Nov 2, 20250
Nov 3, 2025 to Dec 2, 20252
Dec 3, 2025 to Jan 1, 20260
Jan 2, 2026 to Jan 31, 20260
Feb 1, 2026 to Mar 2, 20260
Mar 3, 2026 to Apr 1, 20262
Apr 2, 2026 to May 1, 20260
May 2, 2026 to May 31, 20260
Jun 1, 2026 to Jun 30, 20260
Jul 1, 2026 to Jul 30, 20260
Jul 31, 2026 to Aug 29, 20262
Aug 30, 2026 to Sep 28, 2026 (in progress)4

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

  • Citrix 17 vulnerabilities · 5 in the last 12 months
  • F5 8 vulnerabilities · 2 in the last 12 months
  • Fortinet 3 vulnerabilities · 2 in the last 12 months
  • Ivanti 1 vulnerability
  • Progress 2 vulnerabilities · 1 in the last 12 months

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1Citrix NetScaler ADC / Gateway

    CVE-2026-88771

    Recently addedActive CERT-FR alertHunt for compromise (CISA)

    Citrix NetScaler Improper Input Validation Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 27, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. Rank 2Citrix NetScaler ADC / Gateway

    CVE-2026-88772

    Recently addedActive CERT-FR alertHunt for compromise (CISA)

    Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 27, 2026
    CISA deadline
    3 days
    CVSS severity
    8.1 (high)
  3. Rank 3F5 BIG-IP

    CVE-2026-94127

    Recently addedHunt for compromise (CISA)

    F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 22, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  4. Rank 4Citrix NetScaler ADC / Gateway

    CVE-2026-19490

    Recently addedHunt for compromise (CISA)

    Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 9, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  5. Rank 5Citrix NetScaler ADC / Gateway

    CVE-2026-8452

    Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 26, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  6. Rank 6Progress Kemp LoadMaster

    CVE-2026-8037

    Hunt for compromise (CISA)

    Progress LoadMaster Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 7, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  7. Rank 7Citrix NetScaler ADC / Gateway

    CVE-2026-3055

    Citrix NetScaler Out-of-Bounds Read Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 30, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  8. Rank 8F5 BIG-IP

    CVE-2025-53521

    F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 27, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  9. Rank 9Fortinet FortiWeb

    CVE-2025-64446

    Fortinet FortiWeb Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 14, 2025
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  10. Rank 10Fortinet FortiWeb

    CVE-2025-58034

    Fortinet FortiWeb OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 18, 2025
    CISA deadline
    7 days
    CVSS severity
    7.2 (high)
Show 21 more vulnerabilities
  1. Rank 11Citrix NetScaler ADC / Gateway

    CVE-2025-7775

    Citrix NetScaler Memory Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 26, 2025
    CISA deadline
    2 days
    CVSS severity
    9.8 (critical)
  2. Rank 12Fortinet FortiWeb

    CVE-2025-25257

    Fortinet FortiWeb SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 18, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 13Citrix NetScaler ADC / Gateway

    CVE-2025-6543

    Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 30, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Rank 14Progress Kemp LoadMaster

    CVE-2024-1212

    Progress Kemp LoadMaster OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 15Ivanti Virtual Traffic Manager (vTM)

    CVE-2024-7593

    Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 24, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 16F5 BIG-IP

    CVE-2023-46747

    Ransomware

    F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 31, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 17Citrix NetScaler ADC / Gateway

    CVE-2023-3519

    Ransomware

    Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 19, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 18Citrix NetScaler ADC / Gateway

    CVE-2022-27518

    Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 19F5 BIG-IP

    CVE-2022-1388

    Ransomware

    F5 BIG-IP Missing Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 10, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 20F5 BIG-IP

    CVE-2021-22991

    F5 BIG-IP Traffic Management Microkernel Buffer Overflow

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  11. Rank 21Citrix NetScaler ADC / Gateway

    CVE-2019-19781

    RansomwareCVE from 2019, added in 2021

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  12. Rank 22F5 BIG-IP

    CVE-2020-5902

    Ransomware

    F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  13. Rank 23F5 BIG-IP

    CVE-2021-22986

    Ransomware

    F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  14. Rank 24Citrix NetScaler ADC / Gateway

    CVE-2023-6548

    Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 17, 2024
    CISA deadline
    7 days
    CVSS severity
    8.8 (high)
  15. Rank 25F5 BIG-IP

    CVE-2023-46748

    F5 BIG-IP Configuration Utility SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 31, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  16. Rank 26Citrix NetScaler ADC / Gateway

    CVE-2025-5777

    Ransomware

    Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 10, 2025
    CISA deadline
    1 day
    CVSS severity
    7.5 (high)
  17. Rank 27Citrix NetScaler ADC / Gateway

    CVE-2023-6549

    Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 17, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  18. Rank 28Citrix NetScaler ADC / Gateway

    CVE-2023-4966

    Ransomware

    Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 18, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  19. Rank 29Citrix NetScaler ADC / Gateway

    CVE-2020-8193

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  20. Rank 30Citrix NetScaler ADC / Gateway

    CVE-2020-8195

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.5 (medium)
  21. Rank 31Citrix NetScaler ADC / Gateway

    CVE-2020-8196

    Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    4.3 (medium)

Filed under another category

These 3 vulnerabilities also concern this type of product, but are counted in their main category. My radar finds them when you follow this category.

  1. Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2025-59718

    Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 16, 2025
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  2. Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2024-23113

    Fortinet Multiple Products Format String Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 9, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Fortinet FortiOS / FortiProxy (FortiGate)

    CVE-2018-13374

    RansomwareCVE from 2018, added in 2022

    Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    4.3 (medium)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.