CVE-2025-4365/CVE Unassigned: NetScaler Console/SDX Authenticated Arbitrary File Read/Write (FIXED)


During root cause analysis for the NetScaler Console vulnerability, CVE-2024-6235, Rapid7 discovered two high severity authenticated arbitrary file read and write vulnerabilities which were disclosed to the vendor in accordance with our disclosure policy.

An Arbitrary File Read vulnerability (CVE-2025-4365) was identified in NetScaler Console version 14.1.8.50 and found to affect versions of NetScaler Console and NetScaler SDX 14.1 before 14.1.47.46 and 13.1 before 13.1.58.32, as per the vendor advisory. An Arbitrary File Write vulnerability was identified in NetScaler Console version 14.1.8.50. After disclosing to the vendor, the vendor reported this issue as already being fixed in the latest version of the product.

Read more…
Source: Rapid7


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Google Pixel owners urged to patch actively exploited modem flaw

    September 16, 2026

    Google has released its September 2026 Pixel Update Bulletin, fixing 110 vulnerabilities, including one that it says “may be under limited, targeted exploitation.” The bug is not described as a simple remote takeover, but as a vulnerability that could give an attacker who already has a foothold on a phone more power than they should have. Although ...

  • CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild

    September 15, 2026

    On September 14, 2026, Cisco published a security advisory for CVE-2026-76461, a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance. Cisco Secure ...

  • Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products

    September 15, 2026

    Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products, marking the largest single patch cycle in Cupertino’s history. While this CVE count is hardly notable compared to some vendors – hello, Microsoft’s record-breaking 974 bugs disclosed earlier this month – it does set a company record for ...

  • Microsoft fixes record 964 flaws, including 2 exploited zero-days

    September 9, 2026

    Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, making it the company’s largest Patch Tuesday release on record. Microsoft lists 974 CVEs in its full September security release. However, 10 of those affect cloud services or involve fixes that Microsoft applies itself, leaving 964 vulnerabilities that customers need to patch. The ...

  • MikroTik router flaws allow takeover without a password

    September 8, 2026

    CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet. Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version ...

  • Two major security flaws are affecting more than six million WordPress websites

    September 7, 2026

    More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild. Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms – two popular WordPress plugins. Elementor Pro is a commercial plugin that allows users to build websites using ...