Executive brief
Citrix NetScaler ADC and NetScaler Gateway are network appliances that manage traffic and provide secure access to corporate applications. A vulnerability in these products can allow attackers to remotely execute arbitrary code or crash the appliance, potentially compromising network availability and exposing sensitive data.
Technical details
The vulnerability affects Citrix NetScaler ADC and NetScaler Gateway across multiple versions, enabling remote code execution or denial of service. An attacker with network access to the affected appliance can exploit this issue to execute arbitrary code or disrupt service. Patches are available in versions 14.1-73.37, 13.1-64.23, and their FIPS variants.
Affected products
- Citrix NetScaler ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, before 13.1.37.279 FIPS and NDcPP
- Citrix NetScaler Gateway before 14.1-73.37, before 13.1-64.23
Timeline
- 2026-09-27: disclosed