# Citrix patches six NetScaler ADC flaws

Published: 2026-07-01 · Severity: high
Canonical: https://vorant.io/reports/b9f566c6-b90d-5564-815d-617d7a98387c/citrix-patches-six-netscaler-adc-flaws

> Citrix released patches for multiple vulnerabilities in NetScaler ADC and Gateway products affecting versions 13.1 and 14.1, enabling denial of service and data confidentiality breaches.

The French CERT (CERT-FR) has published an advisory regarding multiple vulnerabilities discovered in Citrix NetScaler ADC and NetScaler Gateway products. The vulnerabilities affect various versions of NetScaler ADC 13.1 and 14.1, including FIPS and NDcPP variants, as well as NetScaler Gateway versions in the same release families.

The vulnerabilities enable attackers to cause remote denial of service, compromise data confidentiality, and trigger additional unspecified security issues as noted by the vendor. Six CVEs have been assigned to track these flaws: CVE-2026-10816, CVE-2026-10817, CVE-2026-13474, CVE-2026-8451, CVE-2026-8452, and CVE-2026-8655. Citrix published security bulletin CTX696604 on June 30, 2026, providing patches for affected versions.

Organizations running affected NetScaler ADC or Gateway versions should prioritize applying the vendor-supplied patches. NetScaler products are commonly deployed as application delivery controllers and VPN gateways in enterprise environments, making them attractive targets for threat actors seeking network access or service disruption.

## Mentioned in this report

- Vulnerabilities: CVE-2026-10816, CVE-2026-10817, CVE-2026-13474, CVE-2026-8451, CVE-2026-8452, CVE-2026-8655

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0822

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b9f566c6-b90d-5564-815d-617d7a98387c/citrix-patches-six-netscaler-adc-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
