High severity7.5NVD Advisory· Published Jun 30, 2026· Updated Jul 2, 2026
CVE-2026-10817
CVE-2026-10817
Description
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Affected products
8cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*+ 3 more
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*range: <13.1-37.272
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*range: <13.1-37.272
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*range: >=13.1,<13.1-63.18
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1-66.68:*:*:*:fips:*:*:*
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*Range: >=13.1,<13.1-63.18
Patches
Vulnerability mechanics
References
1- support.citrix.com/support-home/kbsearch/articlenvdVendor Advisory
News mentions
0No linked articles in our index yet.