
[CIVN-2026-0159] Multiple Vulnerabilities in NetScaler ADC and NetScaler Gateway
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in NetScaler ADC and NetScaler Gateway
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-66.59
NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-62.23
NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.262
NetScaler ADC and NetScaler Gateway 14.1-66.54
Overview
Multiple vulnerabilities have been reported in NetScaler ADC and NetScaler Gateway which could allow an attacker to access sensitive information or cause session integrity issues on the targeted system.
Target Audience:
Organizations and individuals using NetScaler ADC and NetScaler Gateway appliances.
Risk Assessment:
High risk of unauthorised access, system compromise or service disruption.
Impact Assessment:
Potential for Information disclosure, Session integrity issues.
Description
NetScaler ADC is a network appliance used for application delivery and security, while NetScaler Gateway provides secure remote access to enterprise resources.
These vulnerabilities exist in NetScaler ADC and NetScaler Gateway due to Out-of-bounds Read and Race Condition. An attacker could exploit these vulnerabilities by sending specially crafted network requests on the targeted system.
Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information or cause session integrity issues on the targeted system.
Solution
Apply appropriate updates as mentioned in:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300
Vendor Information
Citrix
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300
References
Citrix
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300
CVE Name
CVE-2026-3055
CVE-2026-4368
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmnGlowACgkQ3jCgcSdc
ys9Tpw//TxzW5ADNqGCQSo74XBNDrqLxgHutSp9CfCqoVXpUnPYlkiSuJj6ciBBd
NlBEUXrbPNIXpLK4oAkCgDFfaDvM2k2BeqwO/5nMpSa4FfjZE1LIRVRrhx/ff7m+
bNfNYB1N4p6zpIlmTRuhHTdjHx+gLsOcccVSPzuBSTOrW9EI/AfupDm5N8HUJF6p
ZGRjTuAbfDXRKhDhkPxVTup2r1B3ZoSsOj5uqveAXu0x1TEebJH/82EYmhgFciwy
9yOtD5s+WYiyF3bxoR/UI2noPvI62eWorEIeY9gIveSOsF/hQoyAWqz49L2PBxpK
iopwB3S2/mXirCL6JgbbFBb8lyfN2yKJbX1iDZcssK1J8NaYIUboaVF3L2r82lzs
RdePzldJZ6dtDgmRVYKGeIKuUtfQbl8W8Pi9xxeKjFB+FycNq4GD8gk5kXVZUIWR
i3vKgql7Ua3gxbZqK1pNwBBP3zTxEosgx5wHRv7pvroH+T+51Ty+Ijsz1/GN1HNg
2MqHN9o5sN7CgK8KKLLoYXF9laq62vuFS4IXr01eHuniPNLfpKdSWWGxqZZc3+rC
eklUM9Fi2ZsfsJqOH2zFuyavo+zEFiHVIvxPK79KWuyAvYDDo9jWVX/j9oyWhnmm
9ZAD5kjTM1g6e+7d53AlIqS+7icON03XcHBUfXOovpIUrvxmfpw=
=hNy+
—–END PGP SIGNATURE—–


