【Vulnerability Alert】NetScaler ADC/Gateway Multiple High-Risk Vulnerabilities (CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, CVE-2026-13474). Apply Patches ASAP

publish date : 2026-07-17 update date : 2026-07-17

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026071609072424 Publication Time 2026-07-16 09:52:24
Incident Type ANA-Vulnerability Alert Discovery Time 2026-07-16 09:52:24
Impact Level Middle  
[Subject]
【Vulnerability Alert】NetScaler ADC and NetScaler Gateway Contain Multiple High-Risk Security Vulnerabilities (CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474). Please Confirm and Apply Patches as Soon as Possible
[Content]

Forwarded from the National Institute of Cyber Security Cybersecurity Alert NISAC-200-202607-00000004

Researchers discovered that NetScaler ADC and NetScaler Gateway contain multiple high-risk security vulnerabilities (CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474). The most severe vulnerability, CVE-2026-8452, is a Memory Overflow vulnerability. When an affected device is configured with Gateway or AAA Virtual Server functionality, an unauthenticated remote attacker may exploit this vulnerability to cause system abnormalities, denial of service, or other unexpected behavior. Please confirm and apply patches as soon as possible.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

NetScaler ADC and NetScaler Gateway versions 14.1 to 14.1-72.61 (exclusive)

NetScaler ADC and NetScaler Gateway versions 13.1 to 13.1-63.18 (exclusive)

NetScaler ADC FIPS versions prior to 14.1-72.61 (exclusive)

NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.272 (exclusive)

[Recommended Actions]

The official vendor has released remediation updates for the vulnerabilities. Please refer to the official instructions for updating. The URL is as follows: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604

[Reference]

1. https://nvd.nist.gov/vuln/detail/CVE-2026-8451
2. https://nvd.nist.gov/vuln/detail/CVE-2026-8452
3. https://nvd.nist.gov/vuln/detail/CVE-2026-8655
4. https://nvd.nist.gov/vuln/detail/CVE-2026-10816
5. https://nvd.nist.gov/vuln/detail/CVE-2026-10817
6. https://nvd.nist.gov/vuln/detail/CVE-2026-13474
7. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center