Junglewise Threat Intelligence

CVE-2026-4368: Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA v

CVE-2026-4368 · Severity: info · CVSS 7.7 · Published 2026-03-23

Technologies: Citrix NetScaler ADC, Citrix NetScaler Gateway. Vendors: Citrix.

Executive brief

NetScaler ADC and Gateway appliances are used to provide secure remote access to corporate applications and networks. A vulnerability in these systems could allow a user's session to be incorrectly mixed with another user's session. This could result in unauthorized access to sensitive data or the ability for one user to perform actions on behalf of another.

Technical details

A race condition (CWE-362) exists in NetScaler ADC and NetScaler Gateway appliances. The vulnerability is triggered when the appliance is configured as a Gateway (supporting SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. This flaw in concurrent execution using shared resources leads to 'User Session Mixup,' where session data or identities may be incorrectly associated between different users. An authenticated attacker could potentially exploit this timing issue to gain access to another user's session, compromising confidentiality and integrity. NetScaler has assigned a CVSS 4.0 score of 7.7, indicating a high severity impact.

Affected products

  • Citrix NetScaler ADC
  • Citrix NetScaler Gateway

Timeline

  • 2026-03-23: disclosed
  • 2026-03-23: advisory: Original advisory published by NetScaler/Citrix

References