


Perceptive Security
SOC/SIEM Consultancy

Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
Published:
1 juli 2026 om 03:54:22
Alert date:
1 juli 2026 om 05:00:39
Source:
thehackernews.com
Network Infrastructure, Zero-Day Vulnerabilities, Enterprise Applications
Citrix released security updates addressing multiple vulnerabilities in NetScaler ADC and NetScaler Gateway. The flaws could allow attackers to perform arbitrary file reads or trigger denial-of-service conditions. CVE-2026-8451 carries a CVSS score of 8.8 and is related to insufficient input validation. A total of six vulnerabilities were patched in this update. The affected products were formerly known as Citrix ADC and Citrix Gateway. Organizations using these products are advised to apply the patches promptly to mitigate potential exploitation risks.
Technical details
Citrix released patches for six vulnerabilities in NetScaler ADC and NetScaler Gateway. CVE-2026-8451 (CVSS 8.8) is an insufficient input validation flaw causing memory overread when the appliance is configured as a SAML IDP; it shares the same root cause as CVE-2026-3055 and results in out-of-bounds memory reads via malformed SAML requests, allowing a few bytes of server memory to be leaked per request. CVE-2026-8452 (CVSS 8.8) is a memory overflow leading to unpredictable behavior and DoS when configured as a Gateway or AAA virtual server. CVE-2026-8655 (CVSS 8.8) involves multiple memory overflow vulnerabilities causing DoS when NetScaler ADC is configured as an LB of type Oracle, a DNS Proxy, or a DNS recursive resolver. CVE-2026-10816 (CVSS 7.7) is an external control of file name/path vulnerability enabling unauthenticated arbitrary file read when access to NSIP, Cluster Management IP, or SNIP with management access is enabled. CVE-2026-10817 (CVSS 6.9) is an insufficient input validation flaw causing memory overread when TCP TimeStamp is enabled in a TCP Profile associated with an LB, CS, or VPN virtual server or service. CVE-2026-13474 (CVSS 8.7) is a missing release of memory after effective lifetime (memory leak) vulnerability enabling DoS via malformed HTTP/2 requests when HTTP/2 is enabled in an HTTP Profile associated with an LB, CS, or VPN virtual server or service. CVE-2026-8451 was discovered in late March 2026 by watchTowr during attempts to reproduce CVE-2026-3055. No exploitation in the wild has been observed. Citrix appliances have historically been targeted for ransomware deployment.
Mitigation steps:
1. Upgrade NetScaler ADC and NetScaler Gateway to version 14.1-72.61 or later. 2. Upgrade NetScaler ADC and NetScaler Gateway 13.1 to version 13.1-63.18 or later. 3. Upgrade NetScaler ADC 14.1-FIPS to version 14.1-72.61 FIPS or later. 4. Upgrade NetScaler ADC 13.1-FIPS and 13.1-NDcPP to version 13.1.37.272 or later. 5. For CVE-2026-13474 on appliances NOT using HTTP Strict Profiles (where Http2SmallWndTimeout defaults to 0), manually set the Http2SmallWndTimeout parameter to 30 seconds after upgrading using the command: 'set ns httpProfile <profile_name> -http2SmallWndTimeout <value_in_seconds>'. For appliances using HTTP Strict Profiles, the fix is effective immediately after upgrade as the default is already 30 seconds. 6. Review and restrict management access to NSIP, Cluster Management IP, and SNIP interfaces to mitigate CVE-2026-10816. 7. Monitor for any anomalous SAML authentication requests, malformed HTTP/2 traffic, and unexpected file access attempts as indicators of exploitation.
Affected products:
NetScaler ADC (formerly Citrix ADC) - versions prior to 14.1-72.61
NetScaler Gateway (formerly Citrix Gateway) - versions prior to 14.1-72.61
NetScaler ADC and NetScaler Gateway 13.1 - versions prior to 13.1-63.18
NetScaler ADC 14.1-FIPS - versions prior to 14.1-72.61 FIPS
NetScaler ADC 13.1-FIPS - versions prior to 13.1.37.272
NetScaler ADC 13.1-NDcPP - versions prior to 13.1.37.272
Related links:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604
https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/
https://thehackernews.com/2026/03/citrix-urges-patching-critical.html
https://thehackernews.com/2026/03/citrix-netscaler-under-active-recon-for.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
