Threat Intelligence / CVE / CVE-2025-12101

CVE-2025-12101

CVSS 5.9 · EPSS 25.1% · Priority 9.4/10 · Published 2025-11-11

As of 2025-11-12, CVE-2025-12101 is a CVSS 5.9 vulnerability. Public exploit code available; Nuclei detection template exists. EPSS exploitation probability 25.1%. Threadlinqs Intelligence tracks 1 threat exploiting it.

Last updated: 2025-11-12

Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Weaknesses (CWE)

CWE-79

Exploitation status

public exploit code available · nuclei detection template exists

Threats tracking this CVE

References

Full detection coverage & IOCs for threats exploiting CVE-2025-12101 are available via the Threadlinqs MCP server (Purple tier). View plans →

← all vulnerabilities · Markdown version · Threadlinqs Intelligence

Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.