【Security Vulnerability Alert】NetScaler ADC and NetScaler Gateway have multiple high-risk security vulnerabilities, please confirm and apply patches as soon as possible

 
2026/7/21 ~ 2027/1/21
View Count:39

Forwarded National Information Security Analysis and Sharing Center Security Advisory Alert NISAC-200-202607-00000004

[Description]
Researchers have discovered multiple high-risk security vulnerabilities in NetScaler ADC and NetScaler Gateway (CVE-2026-8451、CVE-2026-8452、CVE-2026-8655、CVE-2026-10816、CVE-2026-10817及CVE-2026-13474). Among them, the most severe CVE-2026-8452 is a memory overflow vulnerability (Memory Overflow). When the affected devices are configured as Gateway or AAA Virtual Server functions, unauthenticated remote attackers can exploit this vulnerability to cause system anomalies, denial of service, or other unexpected behaviors. Please confirm and apply patches as soon as possible.

[Affected Platform]
NetScaler ADC and NetScaler Gateway versions 14.1 to 14.1-72.61 (not including)
NetScaler ADC and NetScaler Gateway versions 13.1 to 13.1-63.18 (not including)
NetScaler ADC FIPS versions prior to 14.1-72.61 (not including)
NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.272 (not including)

[Recommendations]
The official has released fixes for the vulnerabilities. Please refer to the official instructions for updates at the following URL: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604

[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-8451
2. https://nvd.nist.gov/vuln/detail/CVE-2026-8452
3. https://nvd.nist.gov/vuln/detail/CVE-2026-8655
4. https://nvd.nist.gov/vuln/detail/CVE-2026-10816
5. https://nvd.nist.gov/vuln/detail/CVE-2026-10817
6. https://nvd.nist.gov/vuln/detail/CVE-2026-13474
7. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604

Files
None
Top↑