[CIVN-2026-0159] Multiple Vulnerabilities in NetScaler ADC and NetScaler Gateway

By Published On: March 27, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in NetScaler ADC and NetScaler Gateway


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-66.59

NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-62.23

NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.262

NetScaler ADC and NetScaler Gateway 14.1-66.54

Overview


Multiple vulnerabilities have been reported in NetScaler ADC and NetScaler Gateway which could allow an attacker to access sensitive information or cause session integrity issues on the targeted system.


Target Audience:

Organizations and individuals using NetScaler ADC and NetScaler Gateway appliances.


Risk Assessment:

High risk of unauthorised access, system compromise or service disruption.


Impact Assessment:

Potential for Information disclosure, Session integrity issues.


Description


NetScaler ADC is a network appliance used for application delivery and security, while NetScaler Gateway provides secure remote access to enterprise resources.


These vulnerabilities exist in NetScaler ADC and NetScaler Gateway due to Out-of-bounds Read and Race Condition. An attacker could exploit these vulnerabilities by sending specially crafted network requests on the targeted system.


Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information or cause session integrity issues on the targeted system.


Solution


Apply appropriate updates as mentioned in:

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300



Vendor Information


Citrix

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300


References


Citrix

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300


CVE Name

CVE-2026-3055

CVE-2026-4368




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmnGlowACgkQ3jCgcSdc

ys9Tpw//TxzW5ADNqGCQSo74XBNDrqLxgHutSp9CfCqoVXpUnPYlkiSuJj6ciBBd

NlBEUXrbPNIXpLK4oAkCgDFfaDvM2k2BeqwO/5nMpSa4FfjZE1LIRVRrhx/ff7m+

bNfNYB1N4p6zpIlmTRuhHTdjHx+gLsOcccVSPzuBSTOrW9EI/AfupDm5N8HUJF6p

ZGRjTuAbfDXRKhDhkPxVTup2r1B3ZoSsOj5uqveAXu0x1TEebJH/82EYmhgFciwy

9yOtD5s+WYiyF3bxoR/UI2noPvI62eWorEIeY9gIveSOsF/hQoyAWqz49L2PBxpK

iopwB3S2/mXirCL6JgbbFBb8lyfN2yKJbX1iDZcssK1J8NaYIUboaVF3L2r82lzs

RdePzldJZ6dtDgmRVYKGeIKuUtfQbl8W8Pi9xxeKjFB+FycNq4GD8gk5kXVZUIWR

i3vKgql7Ua3gxbZqK1pNwBBP3zTxEosgx5wHRv7pvroH+T+51Ty+Ijsz1/GN1HNg

2MqHN9o5sN7CgK8KKLLoYXF9laq62vuFS4IXr01eHuniPNLfpKdSWWGxqZZc3+rC

eklUM9Fi2ZsfsJqOH2zFuyavo+zEFiHVIvxPK79KWuyAvYDDo9jWVX/j9oyWhnmm

9ZAD5kjTM1g6e+7d53AlIqS+7icON03XcHBUfXOovpIUrvxmfpw=

=hNy+

—–END PGP SIGNATURE—–

Share this article