Executive brief
Citrix NetScaler ADC and Gateway are application delivery controllers and VPN gateways used by enterprises to manage network traffic and secure remote access. A predictable value generation flaw allows an attacker with network access to potentially compromise cryptographic or session mechanisms that depend on randomness, affecting the confidentiality or integrity of protected communications.
Technical details
The vulnerability is a predictable exact value from previous values issue affecting cryptographic or random number generation functions in NetScaler ADC and Gateway. An attacker with network access can exploit this weakness to predict security-critical values, potentially bypassing authentication, session protection, or other security mechanisms. Patches are available for affected versions.
Affected products
- Citrix NetScaler ADC before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, before 13.1.37.279 FIPS and NDcPP
- Citrix NetScaler Gateway before 14.1-73.37, before 13.1-64.23
Timeline
- 2026-09-27: disclosed