
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-10817 is a memory overread vulnerability in Citrix NetScaler ADC and NetScaler Gateway caused by insufficient input validation when the TCP TimeStamp option is enabled in a TCP Profile associated with a virtual server (LB, CS, or VPN type) or a configured service. Disclosed on June 30, 2026, it affects NetScaler ADC and Gateway versions 13.1 before 63.18, 14.1 before 72.61, and NetScaler ADC 13.1 FIPS/NDcPP before 37.272, as well as NetScaler ADC 14.1 FIPS before 72.61. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Citrix Advisory).
The root cause is classified as CWE-125 (Out-of-bounds Read): the NetScaler TCP stack fails to properly validate input when processing TCP packets with the TimeStamp option enabled, allowing an attacker to trigger a read beyond the intended memory buffer boundary. Exploitation requires no authentication, no user interaction, and no special privileges — only that the target instance has TCP TimeStamp enabled in its TCP Profile and that profile is bound to a virtual server or service. The attack is network-accessible and automatable, making it suitable for mass scanning and exploitation. No public proof-of-concept code has been identified at the time of disclosure (GitHub Advisory, Citrix Advisory).
Successful exploitation results in a memory overread that can disclose sensitive information from the NetScaler process memory to an unauthenticated remote attacker, with no impact on integrity or availability of the vulnerable system. The exposed memory could potentially contain session tokens, credentials, cryptographic material, or other sensitive data processed by the appliance, depending on memory layout at the time of exploitation. Given that NetScaler ADC and Gateway are commonly deployed as network perimeter devices handling VPN and load-balancing traffic, memory disclosure could facilitate further attacks against enterprise environments (GitHub Advisory, Citrix Advisory).
derekpreston81/CVE_ADC_IOC_2026, which was noted in threat intelligence as potentially containing IOC data related to this vulnerability class (Feedly).Citrix has released patched versions addressing CVE-2026-10817: NetScaler ADC and Gateway 14.1-72.61 and later, 13.1-63.18 and later, and NetScaler ADC 13.1-37.272 and later (FIPS/NDcPP). As an immediate workaround, administrators should disable the TCP TimeStamp option in the TCP Profile if it is not operationally required, which eliminates the attack surface entirely. Additionally, implementing network-level access controls to restrict traffic to NetScaler services from trusted sources is recommended as a defense-in-depth measure. Upgrading to a patched version is the definitive remediation (Citrix Advisory, GitHub Advisory).
The vulnerability was part of a batch of six NetScaler flaws patched simultaneously, drawing significant media attention. The Stack Technology noted that Citrix credited JPMorgan for responsible disclosure of related vulnerabilities in the same bulletin (The Stack). Security researchers and media outlets drew comparisons to the earlier CitrixBleed vulnerability (CVE-2023-4966) due to the similar memory overread mechanism, with CSO Online reporting exploit attempts in the wild shortly after disclosure (CSO Online). Government cybersecurity agencies including Canada's CCCS and Singapore's CSA issued advisories urging prompt patching (CCCS, CSA Singapore). The Hacker News and multiple security news outlets covered the patch release, emphasizing the unauthenticated nature of the attack (The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."