Executive brief
Citrix NetScaler ADC and NetScaler Gateway are network appliances that manage traffic and application access for enterprises. An improper input validation flaw allows unauthenticated attackers to execute arbitrary commands on affected systems, potentially compromising network infrastructure and sensitive data.
Technical details
The vulnerability is an improper input validation issue in Citrix NetScaler ADC and Gateway that permits unauthenticated remote code execution. An attacker can exploit this without authentication by sending specially crafted input to execute arbitrary commands on the appliance, gaining full system compromise.
Affected products
- Citrix NetScaler ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, before 13.1.37.279 FIPS and NDcPP
- Citrix NetScaler Gateway before 14.1-73.37, before 13.1-64.23
Timeline
- 2026-09-27: disclosed