Security Issues

Five NetScaler ADC and Gateway Vulnerabilities: Configuration-Based Response

A configuration-based guide to five NetScaler ADC and Gateway vulnerabilities, fixed builds, HA rollout and HTTP/2 validation.

Five NetScaler ADC and Gateway vulnerabilities cover
Five NetScaler ADC and Gateway vulnerabilities cover

Five configuration-dependent CVEs

Citrix describes five NetScaler ADC and Gateway CVEs tied to SAML IdP, Gateway or AAA, Oracle load balancing or DNS, management-IP reachability and HTTP/2 profiles. Fixed builds include 14.1-72.61 and 13.1-63.18, with corresponding FIPS builds.

SAML, Gateway and DNS conditions

CVE-2026-8451 requires a SAML IdP configuration. CVE-2026-8452 can cause denial of service on Gateway or AAA virtual servers. CVE-2026-8655 concerns Oracle load balancing, DNS proxy or recursive resolver functions. Inventory each bound feature rather than assigning one generic risk to the appliance.

Management and HTTP/2 boundaries

CVE-2026-10816 permits unauthenticated file reading from a network adjacent to NSIP, CLIP or a management-enabled SNIP. CVE-2026-13474 affects HTTP/2 profiles and also requires operators to verify a 30-second http2SmallWndTimeout for non-HTTP Strict profiles.

Five NetScaler checks for SAML Gateway DNS management and HTTP2
Map each CVE to the actual configuration prerequisite

Upgrade HA and cluster nodes

Back up configuration, certificates and bindings. Upgrade every HA or cluster member through Citrix's supported sequence, validate synchronization and planned failover, and update recovery images. Do not treat one upgraded node as completion.

Service validation

Test SAML IdP, SSL VPN, ICA, CVPN, RDP, AAA, Oracle connectivity, DNS, management access and HTTP/2 according to the configured features. Compare resource metrics and preserve crash or event logs. Completion includes fixed builds on every node, restricted management access and verified HTTP/2 profile settings.

Sources reviewed

  1. NetScaler ADC and NetScaler Gateway Security BulletinCitrix · Official source

SECUFOCUS NOW reorganized and analyzed the material above. This article does not replace the original sources.

READER COMMENTS

Comments

0

No comments yet.

Do not include personal information, advertising, or contact details.