# Citrix Releases Patches for Six NetScaler Flaws: Memory Bugs and Arbitrary File Read Vulnerabilities


Citrix has released security patches addressing six vulnerabilities in NetScaler ADC and NetScaler Gateway that could enable attackers to read arbitrary files or crash critical network infrastructure. The vulnerabilities, ranging from CVSS 6.9 to 8.8, affect organizations relying on these load balancers and identity gateways for core network operations. While there is no evidence of active exploitation, the flaws underscore ongoing memory safety challenges in widely deployed enterprise appliances.


## The Threat


NetScaler ADC and NetScaler Gateway are fundamental components in enterprise network architecture, sitting at the perimeter to load-balance traffic, terminate VPN connections, and mediate SAML authentication flows. The six vulnerabilities disclosed this week span several critical attack vectors: malformed SAML requests, crafted HTTP/2 streams, malicious TCP timestamps, and unauthenticated file path manipulation.


The most significant flaws involve memory safety issues—overreads and overflows that can leak sensitive data or crash the appliance. CVE-2026-8451, discovered by watchTowr Labs, is particularly noteworthy because it mirrors the root cause of CVE-2026-3055 (CVSS 9.3), which was patched earlier in 2026. Both stem from inadequate validation of SAML authentication requests, suggesting the earlier fix may not have addressed the underlying parsing logic comprehensively.


Several of the vulnerabilities require minimal attacker privileges. CVE-2026-10816, rated 7.7, allows unauthenticated arbitrary file reads if management access is exposed—a configuration common in environments where appliances are managed over the network. CVE-2026-13474 exposes a memory leak triggered by malformed HTTP/2 requests, a concern for any organization relying on HTTP/2 for encrypted web traffic.


## Severity and Impact


| CVE ID | CVSS Score | Type | Attack Vector | CWE |

|--------|-----------|------|----------------|-----|

| CVE-2026-8451 | 8.8 | Memory Overread | Network, Unauthenticated | CWE-125 (Out-of-bounds Read) |

| CVE-2026-8452 | 8.8 | Memory Overflow | Network, Unauthenticated | CWE-680 (Integer Overflow) |

| CVE-2026-8655 | 8.8 | Memory Overflow (Multiple) | Network, Unauthenticated | CWE-680 (Integer Overflow) |

| CVE-2026-10816 | 7.7 | Arbitrary File Read | Network, Unauthenticated | CWE-426 (Untrusted Search Path) |

| CVE-2026-10817 | 6.9 | Memory Overread | Network, Low Privileges | CWE-125 (Out-of-bounds Read) |

| CVE-2026-13474 | 8.7 | Memory Leak / DoS | Network, Unauthenticated | CWE-401 (Missing Release of Memory) |


All vulnerabilities are remotely exploitable without authentication or with minimal privileges, making them significant risks for internet-facing deployments.


## Affected Products


NetScaler ADC and NetScaler Gateway (all listed flaws):

  • Versions prior to 14.1-72.61
  • Versions prior to 13.1-63.18 (13.1 branch)

  • NetScaler ADC FIPS (CVE-2026-8451 through CVE-2026-10817):

  • Versions prior to 14.1-72.61 FIPS

  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP (CVE-2026-8451 through CVE-2026-10817):

  • Versions prior to 13.1.37.272

  • NetScaler Gateway is affected by all six flaws when configured as a SAML IDP, AAA virtual server, LB/CS/VPN virtual server, or in DNS proxy roles.


    ## Mitigations


    Immediate Actions:


    1. Apply Patches: Update to NetScaler ADC and Gateway 14.1-72.61, 13.1-63.18, or later versions immediately. Prioritize patching internet-facing instances.


    2. HTTP/2 Configuration (Critical): For CVE-2026-13474, patching alone is insufficient. Administrators must manually configure the HTTP/2 timeout parameter:

    ```

    set ns httpProfile <profile_name> -http2SmallWndTimeout 30

    ```

    This setting defaults to 30 seconds for HTTP Strict Profiles but defaults to 0 (disabled) for standard profiles. The manual configuration change is required for non-Strict Profile deployments.


    3. Network Segmentation: Restrict management access (NSIP, Cluster IP, SNIP) to trusted administrative networks. Disable or limit external access to management interfaces to mitigate CVE-2026-10816.


    4. Disable HTTP/2 Temporarily (if unable to patch immediately): If immediate patching is not feasible, consider disabling HTTP/2 in HTTP Profiles associated with virtual servers until patches are applied.


    5. Monitor for Exploitation: While no exploitation in the wild has been reported, monitor NetScaler logs for malformed SAML requests, TCP timestamp anomalies, and malformed HTTP/2 streams that could indicate attack attempts.


    Longer-Term Considerations:


  • Review SAML configuration and authentication flows; consider implementing additional authentication factors beyond SAML.
  • Audit network configurations to ensure management interfaces are not unnecessarily exposed.
  • Establish a patch management cadence for NetScaler appliances, treating them as critical security infrastructure.

  • ## References


  • Citrix Security Advisory: [https://support.citrix.com/article/CTX596220](https://support.citrix.com/article/CTX596220)
  • watchTowr Labs Technical Analysis: watchTowr's write-up on CVE-2026-8451 and root cause analysis
  • CVE Details: National Vulnerability Database (NVD) CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, CVE-2026-13474

  • ---


    ## HackWire Analysis


    The timing and composition of these six flaws reveal a troubling pattern: Citrix's SAML parsing logic remains fragile, and memory safety issues persist across multiple code paths in NetScaler. That CVE-2026-8451 echoes the root cause of CVE-2026-3055—disclosed just months earlier—suggests the March patch addressed the symptom, not the underlying validation problem. This is a red flag for defenders.


    What makes this patch advisory particularly urgent is the *asymmetry of effort*. Attackers need only craft a malformed SAML request or HTTP/2 stream to trigger crashes or leak memory; defenders must now apply patches *and* manually reconfigure HTTP/2 timeouts on non-Strict Profile deployments. This two-step remediation creates a window where patched appliances remain vulnerable if administrators miss the configuration requirement.


    The discovery credit—JPMorgan Chase's XOR team, watchTowr Labs, and independent researchers—reflects active scrutiny of widely deployed infrastructure. The fact that none of these flaws have been exploited in the wild yet is fortunate, but NetScaler ADC and Gateway sit at the perimeter of thousands of enterprises. Once patches circulate, attackers will reverse-engineer and exploit unpatched instances systematically. Organizations should treat this as a critical infrastructure emergency, not a routine Tuesday patch.


    For security teams, this is also a reminder to scrutinize authentication flows. SAML is a critical trust boundary; if the gateway parsing SAML can be crashed or manipulated, the entire authentication infrastructure becomes suspect. — *HackWire Editorial*


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)