Network and edge
Load balancers and access gateways (ADC)
Appliances placed in front of applications to balance load, filter web traffic or publish remote access.
For example: Citrix NetScaler, F5 BIG-IP, FortiWeb, Kemp LoadMaster.
-
10 vulnerabilities added in the last 12 months
-
31 exploited vulnerabilities in the catalog, in total
-
4 added in the last 30 days
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 4, 2025 to Oct 3, 2025 | 0 |
| Oct 4, 2025 to Nov 2, 2025 | 0 |
| Nov 3, 2025 to Dec 2, 2025 | 2 |
| Dec 3, 2025 to Jan 1, 2026 | 0 |
| Jan 2, 2026 to Jan 31, 2026 | 0 |
| Feb 1, 2026 to Mar 2, 2026 | 0 |
| Mar 3, 2026 to Apr 1, 2026 | 2 |
| Apr 2, 2026 to May 1, 2026 | 0 |
| May 2, 2026 to May 31, 2026 | 0 |
| Jun 1, 2026 to Jun 30, 2026 | 0 |
| Jul 1, 2026 to Jul 30, 2026 | 0 |
| Jul 31, 2026 to Aug 29, 2026 | 2 |
| Aug 30, 2026 to Sep 28, 2026 (in progress) | 4 |
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Citrix 17 vulnerabilities · 5 in the last 12 months
- F5 8 vulnerabilities · 2 in the last 12 months
- Fortinet 3 vulnerabilities · 2 in the last 12 months
- Ivanti 1 vulnerability
- Progress 2 vulnerabilities · 1 in the last 12 months
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Firewalls, VPNs and remote access 111 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
Rank 1Citrix NetScaler ADC / Gateway
CVE-2026-88771Recently addedActive CERT-FR alertHunt for compromise (CISA)
Citrix NetScaler Improper Input Validation Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 27, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 2Citrix NetScaler ADC / Gateway
CVE-2026-88772Recently addedActive CERT-FR alertHunt for compromise (CISA)
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 27, 2026
- CISA deadline
- 3 days
- CVSS severity
- 8.1 (high)
Rank 3F5 BIG-IP
CVE-2026-94127Recently addedHunt for compromise (CISA)
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 22, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 4Citrix NetScaler ADC / Gateway
CVE-2026-19490Recently addedHunt for compromise (CISA)
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 9, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 5Citrix NetScaler ADC / Gateway
CVE-2026-8452Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 26, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 6Progress Kemp LoadMaster
CVE-2026-8037Hunt for compromise (CISA)
Progress LoadMaster Command Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 7, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 7Citrix NetScaler ADC / Gateway
CVE-2026-3055Citrix NetScaler Out-of-Bounds Read Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Mar 30, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 8F5 BIG-IP
CVE-2025-53521F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Mar 27, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 9Fortinet FortiWeb
CVE-2025-64446Fortinet FortiWeb Path Traversal Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Nov 14, 2025
- CISA deadline
- 7 days
- CVSS severity
- 9.8 (critical)
Rank 10Fortinet FortiWeb
CVE-2025-58034Fortinet FortiWeb OS Command Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Nov 18, 2025
- CISA deadline
- 7 days
- CVSS severity
- 7.2 (high)
Show 21 more vulnerabilities
Rank 11Citrix NetScaler ADC / Gateway
CVE-2025-7775Citrix NetScaler Memory Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 26, 2025
- CISA deadline
- 2 days
- CVSS severity
- 9.8 (critical)
Rank 12Fortinet FortiWeb
CVE-2025-25257Fortinet FortiWeb SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 18, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 13Citrix NetScaler ADC / Gateway
CVE-2025-6543Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 30, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 14Progress Kemp LoadMaster
CVE-2024-1212Progress Kemp LoadMaster OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 18, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 15Ivanti Virtual Traffic Manager (vTM)
CVE-2024-7593Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 24, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 16F5 BIG-IP
CVE-2023-46747Ransomware
F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 31, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 17Citrix NetScaler ADC / Gateway
CVE-2023-3519Ransomware
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 19, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 18Citrix NetScaler ADC / Gateway
CVE-2022-27518Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 13, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 19F5 BIG-IP
CVE-2022-1388Ransomware
F5 BIG-IP Missing Authentication Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 10, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 20F5 BIG-IP
CVE-2021-22991F5 BIG-IP Traffic Management Microkernel Buffer Overflow
Added more than a year ago: ranked by severity.
- Added
- Jan 18, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 21Citrix NetScaler ADC / Gateway
CVE-2019-19781RansomwareCVE from 2019, added in 2021
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 22F5 BIG-IP
CVE-2020-5902Ransomware
F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 23F5 BIG-IP
CVE-2021-22986Ransomware
F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 24Citrix NetScaler ADC / Gateway
CVE-2023-6548Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 17, 2024
- CISA deadline
- 7 days
- CVSS severity
- 8.8 (high)
Rank 25F5 BIG-IP
CVE-2023-46748F5 BIG-IP Configuration Utility SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 31, 2023
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 26Citrix NetScaler ADC / Gateway
CVE-2025-5777Ransomware
Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 10, 2025
- CISA deadline
- 1 day
- CVSS severity
- 7.5 (high)
Rank 27Citrix NetScaler ADC / Gateway
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 17, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 28Citrix NetScaler ADC / Gateway
CVE-2023-4966Ransomware
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 18, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 29Citrix NetScaler ADC / Gateway
CVE-2020-8193Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 6.5 (medium)
Rank 30Citrix NetScaler ADC / Gateway
CVE-2020-8195Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 6.5 (medium)
Rank 31Citrix NetScaler ADC / Gateway
CVE-2020-8196Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 4.3 (medium)
Filed under another category
These 3 vulnerabilities also concern this type of product, but are counted in their main category. My radar finds them when you follow this category.
Fortinet FortiOS / FortiProxy (FortiGate)
CVE-2025-59718Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Dec 16, 2025
- CISA deadline
- 7 days
- CVSS severity
- 9.8 (critical)
Fortinet FortiOS / FortiProxy (FortiGate)
CVE-2024-23113Fortinet Multiple Products Format String Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 9, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Fortinet FortiOS / FortiProxy (FortiGate)
CVE-2018-13374RansomwareCVE from 2018, added in 2022
Fortinet FortiOS and FortiADC Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 8, 2022
- CISA deadline
- 21 days
- CVSS severity
- 4.3 (medium)
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.