Executive brief
Citrix NetScaler ADC and Gateway are application delivery controllers that protect and optimize enterprise network traffic. A policy bypass vulnerability allows attackers to circumvent feature policies through improper HTTP URL expression handling, potentially bypassing intended security controls. The impact is limited to policy enforcement weakening rather than direct data exposure or system compromise.
Technical details
The vulnerability stems from improper handling of HTTP URL-based expressions used in feature policies, allowing attackers on the network to craft requests that bypass intended policy controls. Authentication or special privileges are not required for network-based exploitation. A fix is available in patched versions 14.1-73.37 and 13.1-64.23 for both ADC and Gateway products.
Affected products
- Citrix NetScaler ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, before 13.1-64.23 FIPS and NDcPP
- Citrix NetScaler Gateway before 14.1-73.37, before 13.1-64.23
Timeline
- 2026-09-27: disclosed