Cyber Security News

Citrix NetScaler ADC and Gateway Flaws Let Attackers Trigger Memory Overread and Denial-of-Service

Citrix has issued a critical security bulletin addressing multiple high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway.

These vulnerabilities could allow attackers to trigger memory overreads, arbitrary file access, and denial-of-service (DoS) conditions across affected deployments.

The vulnerabilities are tracked as CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474.

They impact widely deployed enterprise networking and remote access infrastructure, raising significant security concerns for organizations that rely on these appliances.

Citrix NetScaler ADC and Gateway Flaws

According to the advisory (CTX696604), the flaws affect NetScaler ADC and Gateway versions 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18, including FIPS and NDcPP variants.

Secure Private Access Hybrid deployments using NetScaler instances are also affected. Notably, Citrix clarified that only customer-managed deployments are impacted, while Citrix-managed cloud services have already been patched.

The most critical issues arise from improper input validation and memory handling errors. CVE-2026-8451, which has a CVSS v4 score of 8.8, is an out-of-bounds read vulnerability (CWE-125) that can lead to memory overread conditions when the appliance is configured as a SAML Identity Provider (IdP).

Attackers exploiting this flaw may gain access to sensitive memory contents, potentially exposing authentication-related data. Similarly, CVE-2026-10817 introduces another memory overread issue related to TCP timestamp handling when enabled in TCP profiles associated with virtual servers.

Another high-risk vulnerability, CVE-2026-8452 (CVSS 8.8), involves a memory overflow condition (CWE-119) that can lead to unpredictable system behavior or service crashes.

This flaw is exploitable when NetScaler is configured as a Gateway (including SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, making it particularly dangerous for remote access environments.

CVE-2026-8655 further expands the attack surface by introducing multiple memory overflow vulnerabilities that affect configurations such as Oracle load balancing, DNS proxy, and recursive DNS resolver deployments.

In addition to the memory corruption flaws, Citrix disclosed CVE-2026-10816, an unauthenticated arbitrary-file-read vulnerability (CVSS 7.1).

This issue can be exploited when attackers have access to management interfaces such as NSIP, SNIP, or Cluster Management IP with management access enabled, potentially exposing sensitive configuration files or system data.

A separate high-severity flaw, CVE-2026-13474 (CVSS 8.7), allows attackers to trigger denial-of-service conditions through specially crafted HTTP/2 requests.

This vulnerability arises due to improper memory handling (CWE-401) when HTTP/2 is enabled in HTTP profiles. Successful exploitation can disrupt services by exhausting system resources through stalled streams.

Citrix has urged customers to immediately upgrade to patched versions, specifically NetScaler ADC and Gateway 14.1-72.61 and 13.1-63.18 or later. For FIPS and NDcPP deployments, corresponding updated builds have also been released. Notably, mitigating CVE-2026-13474 requires additional configuration changes beyond patching.

Administrators must set the newly introduced Http2SmallWndTimeout parameter to 30 seconds, especially in environments that do not use HTTP Strict Profiles, where the default value of 0 does not fully mitigate the issue.

Security teams are advised to review their configurations to determine potential exposure conditions. For instance, environments that use SAML IdP profiles, enable TCP timestamps, or configure HTTP/2 in default or custom HTTP profiles are particularly at risk. Organizations should also audit DNS and Oracle load-balancing configurations that may serve as exploitation prerequisites.

These vulnerabilities were responsibly disclosed by researchers, including Michael Tucker from JPMorgan Chase’s XOR team, Aliz Hammond of watchTowr, and Maxim Suhanov.

Given the prevalence of NetScaler appliances in enterprise environments, these flaws present a high-value target for attackers, especially for initial access, data exposure, and service disruption scenarios. Immediate patching and configuration hardening are essential to reducing the attack surface.

Interact with Cyber Threats in Windows, Linux, macOS VMs to Trigger Full Attack Chain - Analyse Malware & Phishing with ANY RUN

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to…

5 hours ago

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to…

6 hours ago

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS…

6 hours ago

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers…

6 hours ago

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also…

7 hours ago

Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

GitLab has issued an emergency security update to address two critical vulnerabilities that could lead…

8 hours ago