Junglewise Threat Intelligence

CVE-2026-10817: NetScaler ADC and Gateway memory overread in TCP TimeStamp handling

CVE-2026-10817 · Severity: info · CVSS 6.9 · Published 2026-06-30

Technologies: NetScaler Gateway, NetScaler ADC.

Executive brief

NetScaler ADC and Gateway appliances are used to manage network traffic and provide secure remote access to corporate applications. A vulnerability has been identified where improper handling of network timing data could allow an attacker to read sensitive information from the device's memory. This could potentially lead to the exposure of internal system data, though it does not directly allow for system takeover or data modification.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in NetScaler ADC and NetScaler Gateway. The issue is rooted in insufficient input validation of TCP packets when the TCP TimeStamp option is enabled within a TCP Profile associated with a virtual server (Load Balancing, Content Switching, or VPN) or a configured service. A remote, unauthenticated attacker can exploit this over the network to trigger a memory overread, potentially disclosing sensitive information from the system's memory. Patches have been released for affected versions 14.1 and 13.1, including FIPS-validated editions.

Affected products

  • NetScaler ADC 14.1 before 72.61, 13.1 before 63.18, 14.1 FIPS before 72.61, 13.1 FIPS and NDcPP before 37.272
  • NetScaler Gateway 14.1 before 72.61, 13.1 before 63.18

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory

References