By vendor

Citrix vulnerabilities

Known CVEs affecting Citrix products, prioritized by severity, with SEC.co remediation and detection guidance.

4 published vulnerabilities

  • CVE-2026-10816HIGH 7.5

    NetScaler ADC and NetScaler Gateway appliances with management interfaces exposed to the network are vulnerable to unauthenticated attackers reading arbitrary files from the system. An attacker with network access to the management IP address (NSIP, Cluster Management IP, or SNIP configured for management) can exploit a path traversal or similar flaw to extract sensitive files without providing credentials. This is a significant confidentiality risk because management interfaces typically house configuration data, certificates, and other sensitive information.

  • CVE-2026-10817HIGH 7.5

    NetScaler ADC and NetScaler Gateway are vulnerable to a memory disclosure attack when TCP TimeStamp functionality is enabled on TCP profiles associated with load balancing, content switching, VPN virtual servers, or services. An attacker on the network can trigger insufficient input validation to read sensitive data from memory without requiring authentication or user interaction. The vulnerability exposes confidential information but does not allow system disruption or modification.

  • CVE-2026-13474HIGH 7.5

    A denial-of-service vulnerability exists in Citrix NetScaler ADC and NetScaler Gateway when HTTP/2 support is enabled. An unauthenticated attacker can send specially crafted HTTP/2 requests to crash or disable the appliance, causing service interruptions without needing valid credentials or user interaction.

  • CVE-2026-8451HIGH 7.5

    Citrix NetScaler ADC and NetScaler Gateway contain an input validation flaw that can cause the system to read beyond intended memory boundaries when configured to act as a SAML Identity Provider. An unauthenticated network attacker can exploit this condition to extract sensitive data from system memory, potentially including authentication tokens, encryption keys, or other confidential information. The vulnerability requires specific SAML IDP configuration but no user interaction.