Citrix Product Security Update Advisory
Overview
Citrix has released security updates to address vulnerabilities in its NetScaler ADC and NetScaler Gateway products. Users of these products should update to the latest version.
Affected Products
- NetScaler ADC and NetScaler Gateway version 13.1: 13.1 Or higher, but less than 13.1-63.18.
- NetScaler ADC and NetScaler Gateway version 13.1: 13.1 Or higher, but less than 14.1-72.61.
- NetScaler ADC FIPS and NDcPP version 13.1: Versions 13.1 Through 13.1-37.272.
- NetScaler ADC FIPS version 14.1: Versions 14.1 Through 14.1-72.61 FIPS.
Resolved Vulnerabilities
- CVE-2026-8451: Out-of-bounds memory read vulnerability in NetScaler ADC and NetScaler Gateway caused by insufficient input validation.
- CVE-2026-8452: A denial-of-service (DoS) vulnerability in NetScaler ADC and NetScaler Gateway caused by a memory overflow.
- CVE-2026-8655: Denial-of-service (DoS) vulnerability in NetScaler ADC caused by multiple memory overflows.
- CVE-2026-10816: An arbitrary file read vulnerability in NetScaler ADC and NetScaler Gateway.
- CVE-2026-10817: A memory overflow vulnerability in NetScaler ADC and NetScaler Gateway caused by insufficient input validation.
- CVE-2026-13474: Denial-of-service (DoS) vulnerability in NetScaler ADC and NetScaler Gateway caused by malformed HTTP/2 requests (requests that send HTTP/2—a web communication protocol—in an invalid format).
Mitigation
Vulnerability Patches have been provided via the latest updates. Follow the instructions on the reference site to update to the following versions or higher:
- 13.1-63.18 Or higher.
- 14.1-72.61 Or later.
- 13.1-37.272 Or later.
- 14.1-72.61 FIPS or later.