Executive brief
NetScaler ADC and Gateway appliances are susceptible to memory overflow issues that can cause the system to crash or behave erratically. This affects devices specifically configured for Oracle load balancing, DNS proxying, or DNS recursive resolution. An exploit could lead to a denial of service, disrupting network traffic and remote access for the entire organization.
Technical details
NetScaler ADC and Gateway contain multiple memory overflow vulnerabilities triggered under specific configurations: Oracle load balancing, DNS Proxy, or DNS recursive resolver deployments. The root cause is improper memory management when handling these specific protocols or services. A remote, unauthenticated attacker can exploit these flaws over the network to cause a Denial of Service (DoS) or potentially achieve limited data integrity/confidentiality impacts. Patches have been released for versions 14.1 and 13.1, including FIPS-validated builds.
Affected products
- NetScaler ADC 14.1 before 72.61, 13.1 before 63.18, 14.1 FIPS before 72.61, 13.1 FIPS and NDcPP before 37.272
- NetScaler Gateway 14.1 before 72.61, 13.1 before 63.18
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory