Home/Citrix/NetScaler ADC/NetScaler ® Platforms VPX-4 VPX-6 VPX-8 VPX-10 VPX-12 VPX-16 VPX-20 (perpetual release range vCPU based VPX FIPS) EN

NetScaler ® Platforms VPX-4 VPX-6 VPX-8 VPX-10 VPX-12 VPX-16 VPX-20 (perpetual release range vCPU based VPX FIPS) EN

SKU NetScaler-ADC-NetScaler-Platforms-VPX-4-VPX-6-VPX-8-VPX-10-VPX-12-VPX-16-VPX-20-EN

Citrix Virtual Appliance · NetScaler ADC Series

High confidence Official Citrix notice ↗ Verified
NetScaler ® Platforms VPX-4 VPX-6 VPX-8 VPX-10 VPX-12 VPX-16 VPX-20 (perpetual release range vCPU based VPX FIPS) EN is dead. Citrix support ended (-926d). Last available for order .

Is the NetScaler ® Platforms VPX-4 VPX-6 VPX-8 VPX-10 VPX-12 VPX-16 VPX-20 (perpetual release range vCPU based VPX FIPS) EN still supported?

No. Citrix ended support for the NetScaler ® Platforms VPX-4 VPX-6 VPX-8 VPX-10 VPX-12 VPX-16 VPX-20 (perpetual release range vCPU based VPX FIPS) EN on 2024-01-14. No further security fixes will be issued. See Citrix's lifecycle bulletin.

When does the NetScaler ® Platforms VPX-4 VPX-6 VPX-8 VPX-10 VPX-12 VPX-16 VPX-20 (perpetual release range vCPU based VPX FIPS) EN reach end of support?

Citrix support for the NetScaler ® Platforms VPX-4 VPX-6 VPX-8 VPX-10 VPX-12 VPX-16 VPX-20 (perpetual release range vCPU based VPX FIPS) EN ends on 2024-01-14.

What replaces the NetScaler ® Platforms VPX-4 VPX-6 VPX-8 VPX-10 VPX-12 VPX-16 VPX-20 (perpetual release range vCPU based VPX FIPS) EN?

Citrix has not published a successor model for the NetScaler ® Platforms VPX-4 VPX-6 VPX-8 VPX-10 VPX-12 VPX-16 VPX-20 (perpetual release range vCPU based VPX FIPS) EN.

What known-exploited CVEs apply to the NetScaler ® Platforms VPX-4 VPX-6 VPX-8 VPX-10 VPX-12 VPX-16 VPX-20 (perpetual release range vCPU based VPX FIPS) EN past end of support?

16 CVEs in CISA's Known Exploited Vulnerabilities catalog apply to the platform the NetScaler ® Platforms VPX-4 VPX-6 VPX-8 VPX-10 VPX-12 VPX-16 VPX-20 (perpetual release range vCPU based VPX FIPS) EN runs. These will not be patched on this device because it is past the Citrix security-support date. See the Known Exploited Vulnerabilities table below for the full list.

Known Exploited Vulnerabilities

This device is past Citrix's security-support date. 16 CVEs in CISA's Known Exploited Vulnerabilities catalog apply to the platform it runs. Citrix is not issuing patches for this model. Isolate, compensate, or refresh.

CVE KEV added Vulnerability Flags
CVE-2026-3055 Citrix NetScaler Out-of-Bounds Read Vulnerability
CVE-2025-7775 Citrix NetScaler Memory Overflow Vulnerability
CVE-2025-5777 Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability Ransomware
CVE-2025-6543 Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
CVE-2023-6549 Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
CVE-2023-6548 Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
CVE-2023-4966 Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability Ransomware
CVE-2023-3519 Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability Ransomware
CVE-2022-27518 Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability
CVE-2019-12991 Citrix SD-WAN and NetScaler Command Injection Vulnerability
CVE-2019-12989 Citrix SD-WAN and NetScaler SQL Injection Vulnerability
CVE-2017-6316 Citrix Multiple Products Remote Code Execution Vulnerability
CVE-2020-8193 Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
CVE-2020-8195 Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
CVE-2020-8196 Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
CVE-2019-19781 Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability Ransomware

Source: CISA Known Exploited Vulnerabilities catalog. The Ransomware flag reflects CISA's own knownRansomwareCampaignUse field, set when the CVE has been observed in ransomware campaigns per their threat intel. It's not a property of the vulnerability description itself.

Correlation is at the platform level, not per-OS-version. Not exhaustive: KEV only lists actively-exploited CVEs and many relevant unexploited vulnerabilities are not here. Verify against vendor security advisories (PSIRT, JSA, PAN-SA) and NVD before acting. See compensating controls if refresh isn't immediate.

NetScaler ® Platforms VPX-4 VPX-6 VPX-8 VPX-10 VPX-12 VPX-16 VPX-20 (perpetual release range vCPU based VPX FIPS) EN Lifecycle Overview

The Citrix NetScaler ® Platforms VPX-4 VPX-6 VPX-8 VPX-10 VPX-12 VPX-16 VPX-20 (perpetual release range vCPU based VPX FIPS) EN (NetScaler-ADC-NetScaler-Platforms-VPX-4-VPX-6-VPX-8-VPX-10-VPX-12-VPX-16-VPX-20-EN) is a virtual appliance product in the Citrix NetScaler ADC series. This product has reached end of life as of , meaning Citrix no longer provides technical support, software updates, or hardware replacement for this product. It was last available for purchase on . Organizations still running the NetScaler ® Platforms VPX-4 VPX-6 VPX-8 VPX-10 VPX-12 VPX-16 VPX-20 (perpetual release range vCPU based VPX FIPS) EN should plan a migration .

Lifecycle Milestones

Lifecycle notice published 5y 6mo ago
End of sale 5y 6mo ago
End of software maintenance 2y 6mo ago
Last date of support 2y 6mo ago
Applicable Platforms
↑ Top