By Lucas Martin
Publication Date: 2026-07-01 08:20:00
Cloud Software Group has disclosed six vulnerabilities affecting NetScaler ADC and NetScaler Gateway, several of which carry High severity ratings and could allow attackers to trigger denial-of-service conditions, read arbitrary files, or overread sensitive memory.
The bulletin, tracked as CTX696604, covers CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474.
The most severe issues, CVE-2026-8451 and CVE-2026-8452, each score 8.8 on the CVSSv4 scale. CVE-2026-8451 stems from insufficient input validation on appliances configured as a SAML IdP, enabling out-of-bounds memory reads (CWE-125). ‘
Citrix NetScaler ADC and Gateway Flaws
CVE-2026-8452 involves a memory overflow (CWE-119) affecting Gateway configurations (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers, leading to unpredictable behavior and DoS attacks.
CVE-2026-8655, also scored 8.8, affects appliances configured as an Oracle-type load balancer, DNS…



