NCSC-2026-0216 [1.01] [M/H] Vulnerabilities Fixed in Citrix Netscaler ADC and Netscaler Gateway
Citrix has fixed vulnerabilities in NetScaler ADC and NetScaler Gateway related to insufficient input validation, improper access control, and improper memory release. The vulnerabilities identified as CVE-2026-8451 and CVE-2026-10817 result from insufficient input validation, where the software does not correctly check input sizes and boundaries. This can lead to memory over-reads, which can result in unauthorized disclosure of sensitive information, when the products are configured as SAML IDP, or when TCP TimeStamp is enabled on a TCP profile associated with a virtual server of type: Load Balancing (LB), Content Switching (CS), or VPN. The vulnerabilities identified as CVE-2026-8452 and CVE-2026-8655 are in the way memory is managed in NetScaler ADC and NetScaler Gateway. This can lead to a denial-of-service (DoS) or unintended control flow when the products are configured as Gateway, DNS-proxy, recursive DNS-resolver, or AAA virtual server. The vulnerability identified as CVE-2026-13474 results from improper memory release. Malicious actors can exploit this vulnerability by causing a denial-of-service (DoS) through specially crafted HTTP/2 requests. The vulnerability identified as CVE-2026-10816 concerns an access control issue within the Management Interface. Remote unauthenticated malicious actors can exploit the vulnerability to read arbitrary files. This can result in unauthorized disclosure of sensitive information. Researchers have shared Proof-of-Concept (PoC) code demonstrating the vulnerability identified as CVE-2026-8451. UPDATE: Meanwhile, the same researchers have also published Proof-of-Concept (PoC) code enabling arbitrary code execution. For this, the vulnerable system must be configured to authenticate via SAML
CSIRTS triage
- What
- Insufficient input validation and improper memory management vulnerabilities cause memory over-reads leading to information disclosure and denial of service.
- Who is affected
- Citrix NetScaler ADC and Gateway deployments configured as SAML IDP, with TCP TimeStamp enabled, or configured as Gateway.
- Urgency
- High severity on exposed configurations; information disclosure of sensitive data and DoS require urgent patching for affected deployments.
- Action
- Apply Citrix patches for CVE-2026-8451, CVE-2026-10817, CVE-2026-8452, CVE-2026-8655, CVE-2026-13474, and CVE-2026-10816 on affected configurations.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch NetScaler ADC and NetScaler Gateway
Get an email when a new NetScaler ADC and NetScaler Gateway advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0216
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Elevated exploitation riskCVE-2026-845115.7% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 97% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-108170.56% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-8452Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 74% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-86550.63% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-134740.56% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-108160.58% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-8451 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-10817 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8452 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8655 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13474 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-10816 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploited[UPDATE] [high] Citrix Systems NetScaler ADC and Gateway: Multiple vulnerabilitiescert-bund
- criticalexploitedCitrix security advisory (AV26-645) – Update 3cccs
- highexploitedCISA Adds Six Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-8452: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds…cisa-kev
- unknownCitrix Products Multiple Vulnerabilitieshkcert
- unknownAL26-016 - Vulnerability impacting Citrix NetScaler CVE-2026-8451cccs
- unknownMultiple vulnerabilities in Citrix products (July 1, 2026)cert-fr-avis
- unknownNCSC-2026-0216 [1.00] [M/H] Vulnerabilities fixed in Citrix Netscaler ADC and Netscaler Gatewayncsc-nl
- criticalCVE-2026-8655: Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpr…nvd
- criticalCVE-2026-8452: Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or e…nvd
- highCVE-2026-8451: Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread…nvd
- highCVE-2026-13474: Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP…nvd
Recent advisories for Citrix Netscaler ADC
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0318 [1.01] [H/H] Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gatewayncsc-nl · 2026-09-07
- critical[UPDATE] [kritisch] Citrix Systems NetScaler (Gateway und ADC): Mehrere Schwachstellencert-bund · 2026-09-07
- unknownAL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-…cccs · 2026-09-04
- criticalexploited[UPDATE] [high] Citrix Systems NetScaler ADC and Gateway: Multiple vulnerabilitiescert-bund · 2026-08-27
- criticalexploitedCVE-2026-8452: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds…cisa-kev · 2026-08-26
- unknownNCSC-2026-0318 [1.00] [M/M] Vulnerabilities resolved in Citrix NetScaler ADC and NetScaler Gatewayncsc-nl · 2026-08-20
More from NCSC-NL Advisories
- unknownNCSC-2026-0353 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Windows2026-09-08
- unknownNCSC-2026-0352 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Office2026-09-08
- unknownNCSC-2026-0351 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Developer Tools2026-09-08
- unknownNCSC-2026-0350 [1.00] [M/H] Kwetsbaarheden verholpen in SQL Server2026-09-08
- unknownNCSC-2026-0349 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Exchange server2026-09-08