Overview
What is CVE-2025-12101?
Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Vulnerability intelligence
CVE-2025-12101 and is rated Medium severity with a CVSS score of 5.9. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server