VORANT. Threat Intelligence Sign in Get the full feed

Citrix patches six NetScaler ADC flaws

high vulnerability

Citrix released patches for multiple vulnerabilities in NetScaler ADC and Gateway products affecting versions 13.1 and 14.1, enabling denial of service and data confidentiality breaches.

The French CERT (CERT-FR) has published an advisory regarding multiple vulnerabilities discovered in Citrix NetScaler ADC and NetScaler Gateway products. The vulnerabilities affect various versions of NetScaler ADC 13.1 and 14.1, including FIPS and NDcPP variants, as well as NetScaler Gateway versions in the same release families.

The vulnerabilities enable attackers to cause remote denial of service, compromise data confidentiality, and trigger additional unspecified security issues as noted by the vendor. Six CVEs have been assigned to track these flaws: CVE-2026-10816, CVE-2026-10817, CVE-2026-13474, CVE-2026-8451, CVE-2026-8452, and CVE-2026-8655. Citrix published security bulletin CTX696604 on June 30, 2026, providing patches for affected versions.

Organizations running affected NetScaler ADC or Gateway versions should prioritize applying the vendor-supplied patches. NetScaler products are commonly deployed as application delivery controllers and VPN gateways in enterprise environments, making them attractive targets for threat actors seeking network access or service disruption.

Mentioned in this report

Vulnerabilities CVE-2026-10816CVE-2026-10817CVE-2026-13474CVE-2026-8451CVE-2026-8452CVE-2026-8655

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0822

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free