Citrix has released urgent security updates for its NetScaler ADC and NetScaler Gateway products , addressing six critical vulnerabilities that could allow malicious actors to perform arbitrary file reads or cause denial -of-service (DoS) attacks. There is no evidence of exploitation yet, but the history of NetScaler vulnerabilities makes immediate updates imperative.

The six vulnerabilities disclosed are tracked as: CVE-2026-8451 ( CVSS 8.8 ), CVE-2026-8452 ( CVSS 8.8 ), CVE-2026-8655 ( CVSS 8.8 ), CVE-2026-10816 ( CVSS 7.7 ), CVE-2026-10817 ( CVSS 6.9 ), and CVE-2026-13474 ( CVSS 8.7 ). Four of the six vulnerabilities involve memory management issues ( memory overread and memory overflow ), a pattern that directly references the infamous CitrixBleed attacks of 2023. The discovery and reporting of the vulnerabilities is credited to Michael Tucker of JPMorgan Chase 's XOR team , Aliz Hammond of watchTowr , and Maxim Suhanov .
See also: Citrix patches vulnerabilities in NetScaler ADC and Gateway
It is worth noting that the disclosure by JPMorgan Chase — the largest US bank — is a milestone, as it is the first time the bank has received public recognition for a vulnerability disclosure.
Citrix released updates on June 30, 2026 under bulletin AV26-645 , while the Canadian Centre for Cyber Security was quick to highlight the severity of the vulnerabilities.
NetScaler: Technical details of the vulnerabilities
CVE -2026-8451 concerns insufficient input validation leading to memory overread when NetScaler ADC or NetScaler Gateway is configured as a SAML IDP.
CVE -2026-8452 concerns a memory overflow that leads to unpredictable behavior and DoS when the device acts as a Gateway or AAA virtual server (SSL VPN, ICA Proxy, CVPN, RDP Proxy).
CVE -2026-8655 concerns multiple memory overflow that occur when NetScaler ADC functions as an Oracle load balancer, DNS Proxy , or DNS recursive resolver.
See also: Amazon: Cisco ISE and Citrix NetScaler zero-day exploit
CVE -2026-10816 is particularly concerning as it allows unauthenticatedarbitrary filewhen access to NSIP, Cluster Management IP , or SNIP with administrative privileges is enabled.
CVE -2026-13474 can lead to DoS via malformed HTTP/2 requests when HTTP/2 is enabled. For this vulnerability, Citrix recommends additionally modifying the Http2SmallWndTimeout parameter : for devices using HTTP Strict Profiles the default value is 30 seconds and the update is sufficient, while for devices without HTTP Strict Profiles the default value is 0 and a manual setting to 30 seconds is required .

NetScaler: Affected versions and update instructions
The vulnerabilities affect NetScaler ADC/Gateway versions 14.1 (before 14.1-72.61 ) and 13.1 (before 13.1-63.18 ), including FIPS and NDcPP versions .
The fixes are provided in the following versions:
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later versions of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later versions of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later versions of 13.1-FIPS and 13.1-NDcPP
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Hammond pointed to the broader problem: “ What we should be concerned about is the bigger picture — the trend that clearly suggests that memory management continues to appear fragile in Citrix NetScaler, to the point where even accidentally misconfiguring an appliance can lead to a memory leak appliances .” This observation is particularly important in light of the 2023 CitrixBleed attacks, where CVE-2023-4966 allowed threat actors to steal session tokens from memory and bypass multi-factor authentication (MFA) .
See also: Citrix: NetScaler vulnerability used for DoS attacks

To protect systems immediately, organizations should proceed with an immediate update. If this is not possible, it is recommended to disable HTTP/2 or vulnerable functions Gatewaywhere they are not necessary. According to The Hacker News, there is no evidence of exploitation yet, but the history of NetScaler vulnerabilities as high-value targets for cybercriminals makes immediate action absolutely necessary.
