Citrix has released security updates to address six vulnerabilities in NetScaler ADC and NetScaler Gateway, including flaws that could allow arbitrary file reads or denial-of-service (DoS) attacks. The vulnerabilities are:
- CVE-2026-8451 (CVSS 8.8): Insufficient input validation leading to memory overread when configured as a SAML IDP.
- CVE-2026-8452 (CVSS 8.8): Memory overflow causing DoS when configured as a Gateway or AAA virtual server.
- CVE-2026-8655 (CVSS 8.8): Multiple memory overflow vulnerabilities leading to DoS when configured as an LB of type Oracle, DNS Proxy, or DNS recursive resolver.
- CVE-2026-10816 (CVSS 7.7): External control of file name leading to unauthenticated arbitrary file read when management access is enabled.
- CVE-2026-10817 (CVSS 6.9): Insufficient input validation leading to memory overread when TCP TimeStamp is enabled.
- CVE-2026-13474 (CVSS 8.7): Missing release of memory after effective lifetime leading to DoS via malformed HTTP/2 requests.
Patches are available in versions 14.1-72.61, 13.1-63.18, and corresponding FIPS/NDcPP releases. For CVE-2026-13474, customers must manually set the Http2SmallWndTimeout parameter to 30 seconds if not using HTTP Strict Profiles. The vulnerabilities were reported by researchers from JPMorgan Chase, watchTowr, and Maxim Suhanov. No active exploitation has been observed, but Citrix appliances remain a frequent target for threat actors.
CVEs: CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, CVE-2026-13474, CVE-2026-3055, CVE-2026-20245
Companies: Citrix, JPMorgan Chase, watchTowr
Products: NetScaler ADC, NetScaler Gateway
Original source: thehackernews.com