CVE-2026-10817
Citrix ADC VPX vulnerability analysis and mitigation

Overview

CVE-2026-10817 is a memory overread vulnerability in Citrix NetScaler ADC and NetScaler Gateway caused by insufficient input validation when the TCP TimeStamp option is enabled in a TCP Profile associated with a virtual server (LB, CS, or VPN type) or a configured service. Disclosed on June 30, 2026, it affects NetScaler ADC and Gateway versions 13.1 before 63.18, 14.1 before 72.61, and NetScaler ADC 13.1 FIPS/NDcPP before 37.272, as well as NetScaler ADC 14.1 FIPS before 72.61. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Citrix Advisory).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read): the NetScaler TCP stack fails to properly validate input when processing TCP packets with the TimeStamp option enabled, allowing an attacker to trigger a read beyond the intended memory buffer boundary. Exploitation requires no authentication, no user interaction, and no special privileges — only that the target instance has TCP TimeStamp enabled in its TCP Profile and that profile is bound to a virtual server or service. The attack is network-accessible and automatable, making it suitable for mass scanning and exploitation. No public proof-of-concept code has been identified at the time of disclosure (GitHub Advisory, Citrix Advisory).

Impact

Successful exploitation results in a memory overread that can disclose sensitive information from the NetScaler process memory to an unauthenticated remote attacker, with no impact on integrity or availability of the vulnerable system. The exposed memory could potentially contain session tokens, credentials, cryptographic material, or other sensitive data processed by the appliance, depending on memory layout at the time of exploitation. Given that NetScaler ADC and Gateway are commonly deployed as network perimeter devices handling VPN and load-balancing traffic, memory disclosure could facilitate further attacks against enterprise environments (GitHub Advisory, Citrix Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing NetScaler ADC or Gateway instances running vulnerable versions (13.1 < 63.18 or 14.1 < 72.61) using tools such as Shodan, Censys, or Masscan, targeting common NetScaler management and data ports.
  2. Verify TCP TimeStamp configuration: Confirm that the target has TCP TimeStamp enabled in its TCP Profile bound to a virtual server (LB, CS, or VPN type) or service — this is the required precondition for exploitation.
  3. Craft malicious TCP packets: Construct TCP packets with a malformed or specially crafted TCP TimeStamp option field designed to trigger insufficient input validation in the NetScaler TCP stack.
  4. Trigger memory overread: Send the crafted packets to the target virtual server or service endpoint; the insufficient validation causes the appliance to read beyond the intended buffer boundary.
  5. Collect disclosed memory: Capture the response data returned by the appliance, which may contain fragments of process memory including session tokens, credentials, or other sensitive data (GitHub Advisory, Citrix Advisory).

Indicators of compromise

  • Network: Anomalous TCP connections to NetScaler virtual server or service ports with malformed or unusual TCP TimeStamp option values; high volumes of TCP packets with crafted option fields from a single or rotating source IP.
  • Logs: NetScaler system logs showing unexpected TCP processing errors or memory-related warnings; unusual traffic patterns in ns.log or newnslog correlated with TCP option handling.
  • File System: Presence of the GitHub repository derekpreston81/CVE_ADC_IOC_2026, which was noted in threat intelligence as potentially containing IOC data related to this vulnerability class (Feedly).
  • Process: Unexpected crashes or restarts of NetScaler packet processing daemons that could indicate repeated exploitation attempts triggering memory access violations.

Mitigation and workarounds

Citrix has released patched versions addressing CVE-2026-10817: NetScaler ADC and Gateway 14.1-72.61 and later, 13.1-63.18 and later, and NetScaler ADC 13.1-37.272 and later (FIPS/NDcPP). As an immediate workaround, administrators should disable the TCP TimeStamp option in the TCP Profile if it is not operationally required, which eliminates the attack surface entirely. Additionally, implementing network-level access controls to restrict traffic to NetScaler services from trusted sources is recommended as a defense-in-depth measure. Upgrading to a patched version is the definitive remediation (Citrix Advisory, GitHub Advisory).

Community reactions

The vulnerability was part of a batch of six NetScaler flaws patched simultaneously, drawing significant media attention. The Stack Technology noted that Citrix credited JPMorgan for responsible disclosure of related vulnerabilities in the same bulletin (The Stack). Security researchers and media outlets drew comparisons to the earlier CitrixBleed vulnerability (CVE-2023-4966) due to the similar memory overread mechanism, with CSO Online reporting exploit attempts in the wild shortly after disclosure (CSO Online). Government cybersecurity agencies including Canada's CCCS and Singapore's CSA issued advisories urging prompt patching (CCCS, CSA Singapore). The Hacker News and multiple security news outlets covered the patch release, emphasizing the unauthenticated nature of the attack (The Hacker News).

Additional resources


SourceThis report was generated using AI

Related Citrix ADC VPX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8655HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-8452HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-8451HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-13474HIGH8.7
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-10817MEDIUM6.9
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management