By Cyber Security Agency of Singapore
Publication Date: 2026-07-02 00:00:00
Background
Citrix has released security updates to address multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway.
These vulnerabilities have Common Vulnerability Scoring System (CVSS v4.0) scores of: CVE-2026-8451 at 8.8, CVE-2026-8452 at 8.8, CVE-2026-8655 at 8.8, CVE-2026-10816 at 7.1, CVE-2026-10817 at 6.9, and CVE-2026-13474 at 8.7 out of 10.
Impact
Successful exploitation of these vulnerabilities could lead to the following:
CVE-2026-8451: Due to insufficient input validation, an attacker could trigger memory overread when NetScaler ADC or NetScaler Gateway is configured as a SAML Identity Provider (IDP), potentially disclosing sensitive memory content
s.
CVE-2026-8452: Due to a memory overflow vulnerability, an attacker could cause unpredictable or erroneous behaviour and denial-of-service when the appliance is configured as a Gateway or an AAA virtual server.
CVE-2026-8655: Due to multiple memory overflow vulnerabilities, an attacker could cause unpredictable or…


