Multiple vulnerabilities in Citrix products (July 1, 2026)
Multiple vulnerabilities have been discovered in Citrix products. Some of them allow an attacker to cause remote denial of service, data confidentiality breaches, and an unspecified security issue by the vendor.
CSIRTS triage
- What
- Multiple vulnerabilities in Citrix products can lead to remote denial of service and data confidentiality breaches.
- Who is affected
- Users of Citrix products are affected.
- Urgency
- Remediation is important due to the potential for exploitation and medium severity.
- Action
- Check for and apply updates for Citrix products to address these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0822/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-84521.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
- Elevated exploitation riskCVE-2026-845115.7% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 97% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-108170.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-108160.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-86550.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-134740.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-8452 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8451 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-10817 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-10816 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8655 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13474 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0216 [1.01] [M/H] Vulnerabilities Fixed in Citrix Netscaler ADC and Netscaler Gatewayncsc-nl
- criticalCitrix security advisory (AV26-645) – Update 2cccs
- unknownCitrix Products Multiple Vulnerabilitieshkcert
- unknownAL26-016 - Vulnerability impacting Citrix NetScaler CVE-2026-8451cccs
- high[UPDATE] [high] Citrix Systems NetScaler ADC and Gateway: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0216 [1.00] [M/H] Vulnerabilities fixed in Citrix Netscaler ADC and Netscaler Gatewayncsc-nl
- criticalCVE-2026-8655: Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpr…nvd
- criticalCVE-2026-8452: Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or e…nvd
- highCVE-2026-8451: Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread…nvd
- highCVE-2026-13474: Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP…nvd
- highCVE-2026-10817: Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gatewa…nvd
- highCVE-2026-10816: Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to …nvd
Recent advisories for Citrix products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMultiple vulnerabilities in Citrix products (20 August 2026)cert-fr-avis · 2026-08-20
- unknownMultiple Vulnerabilities in Citrix Products (July 15, 2026)cert-fr-avis · 2026-07-15
- unknownCitrix Products Multiple Vulnerabilitieshkcert · 2026-07-03
- criticalexploitedCVE-2017-6316: Citrix Multiple Products Remote Code Execution Vulnerabilitycisa-kev · 2022-03-25
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21