Five NetScaler ADC and Gateway Vulnerabilities: Configuration-Based Response
A configuration-based guide to five NetScaler ADC and Gateway vulnerabilities, fixed builds, HA rollout and HTTP/2 validation.

Five configuration-dependent CVEs
Citrix describes five NetScaler ADC and Gateway CVEs tied to SAML IdP, Gateway or AAA, Oracle load balancing or DNS, management-IP reachability and HTTP/2 profiles. Fixed builds include 14.1-72.61 and 13.1-63.18, with corresponding FIPS builds.
SAML, Gateway and DNS conditions
CVE-2026-8451 requires a SAML IdP configuration. CVE-2026-8452 can cause denial of service on Gateway or AAA virtual servers. CVE-2026-8655 concerns Oracle load balancing, DNS proxy or recursive resolver functions. Inventory each bound feature rather than assigning one generic risk to the appliance.
Management and HTTP/2 boundaries
CVE-2026-10816 permits unauthenticated file reading from a network adjacent to NSIP, CLIP or a management-enabled SNIP. CVE-2026-13474 affects HTTP/2 profiles and also requires operators to verify a 30-second http2SmallWndTimeout for non-HTTP Strict profiles.

Upgrade HA and cluster nodes
Back up configuration, certificates and bindings. Upgrade every HA or cluster member through Citrix's supported sequence, validate synchronization and planned failover, and update recovery images. Do not treat one upgraded node as completion.
Service validation
Test SAML IdP, SSL VPN, ICA, CVPN, RDP, AAA, Oracle connectivity, DNS, management access and HTTP/2 according to the configured features. Compare resource metrics and preserve crash or event logs. Completion includes fixed builds on every node, restricted management access and verified HTTP/2 profile settings.
Sources reviewed
SECUFOCUS NOW reorganized and analyzed the material above. This article does not replace the original sources.



Comments
No comments yet.