Executive brief
Citrix NetScaler ADC and Gateway are load balancing and application delivery appliances used to optimize and secure network traffic to critical applications. A memory overflow vulnerability in these products could allow an attacker to trigger unpredictable behavior or denial of service, potentially disrupting access to protected applications and services.
Technical details
A memory overflow vulnerability exists in Citrix NetScaler ADC and NetScaler Gateway that can result in unpredictable or erroneous behavior or denial of service. The vulnerability affects multiple product versions across ADC and Gateway product lines. Patched versions are available and should be deployed to mitigate the issue.
Affected products
- Citrix NetScaler ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, before 13.1.37.279 FIPS and NDcPP
- Citrix NetScaler Gateway before 14.1-73.37, before 13.1-64.23
Timeline
- 2026-09-27: disclosed