Citrix released security updates for its NetScaler ADC and NetScaler Gateway products on Tuesday, addressing six vulnerabilities. These patches target issues including high-severity out-of-bounds read, memory overflow, and arbitrary file read bugs, along with a specific variant of the HTTP/2 Bomb denial-of-service exploit.
Four of the vulnerabilities are tracked as CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, and CVE-2026-10816. CVE-2026-10816 is also classified as a medium-severity out-of-bounds read. The HTTP/2 Bomb vulnerability, which causes web servers to go offline by combining known attack techniques, is generally tracked as CVE-2026-49975, but Citrix assigned a NetScaler-specific identifier, CVE-2026-13474, for its version. The HTTP/2 Bomb was discovered using OpenAI’s Codex.
The security updates apply to NetScaler ADC and NetScaler Gateway versions 14.1-72.61 and 13.1-63.18. Additionally, NetScaler ADC FIPS version 14.1-72.61 FIPS, and NetScaler ADC FIPS and NDcPP version 13.1-37.272 have also received patches. Citrix stated that each vulnerability has different configuration-specific preconditions and advised customers to assess if their deployments have the vulnerable features activated.
Attack surface management firm watchTowr stated that CVE-2026-8451 has a CVSS score of 8.8 and is considered the latest in the CitrixBleed series of security defects. watchTowr added that CVE-2026-8451 affects NetScaler’s XML parser, which reads beyond the intended limits of each XML attribute value. This can trick NetScaler into returning restricted memory in an HTTP response, according to watchTowr.
watchTowr explained that successful exploitation of CVE-2026-8451 requires the NetScaler instance to be configured as SAML IDP, and the attacker’s login request must meet specific criteria. An attacker could use CVE-2026-8451 to leak data from a vulnerable appliance. This leaked data might include a data pointer that, when combined with a memory corruption issue, could lead to a complete compromise of the device. Organizations utilizing self-managed NetScaler ADC, NetScaler Gateway, and Citrix Secure Private Access Hybrid deployments that use NetScaler instances are advised to implement the patches.
forum Comments (0)
No comments yet. Be the first to comment.