CVE-2026-4368
Citrix ADC VPX vulnerability analysis and mitigation

Overview

CVE-2026-4368 is a race condition vulnerability in Citrix NetScaler ADC and NetScaler Gateway that leads to User Session Mixup when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. It was published on March 23, 2026, and affects NetScaler ADC and Gateway versions prior to 14.1.66.54. The vulnerability is classified as CWE-362 (Race Condition) and carries a CVSS v4.0 base score of 7.7 (High) (Feedly, Citrix Advisory). It is disclosed alongside CVE-2026-3055, a critical out-of-bounds memory read affecting the same products.

Technical details

The vulnerability is rooted in improper synchronization of concurrent execution using shared session resources (CWE-362 / CAPEC-26: Leveraging Race Conditions). When the NetScaler appliance processes simultaneous authentication or session establishment requests under Gateway or AAA virtual server configurations, a timing window allows session state to be incorrectly assigned between users — resulting in session mixup. Exploitation requires the attacker to have low-level authenticated access and the presence of specific race condition timing (Attack Requirements: PRESENT in CVSS v4.0), meaning it is not trivially automatable but is feasible under concurrent load conditions. Technical analysis has been published by Picus Security and Horizon3.ai in the context of the broader NetScaler vulnerability cluster dubbed "CitrixBleed 3" (Picus Security, Horizon3.ai).

Impact

Successful exploitation can result in high confidentiality, integrity, and availability impact on the vulnerable system (CVSS v4.0 VC:H/VI:H/VA:H). An authenticated attacker who wins the race condition may gain access to another user's active session, potentially exposing sensitive session tokens, credentials, or data transmitted through the VPN or proxy. This session mixup could enable lateral movement within enterprise networks by hijacking privileged user sessions, and may allow unauthorized actions to be performed on behalf of other authenticated users (Feedly, Picus Security).

Exploitability

CVE-2026-4368 has an EPSS score of approximately 0.018% (0.000180), indicating a currently low but non-negligible probability of exploitation in the wild. The vulnerability is disclosed alongside CVE-2026-3055, which has been confirmed as actively exploited and added to the CISA Known Exploited Vulnerabilities (KEV) catalog (CISA KEV commit, BleepingComputer). While active exploitation of CVE-2026-4368 specifically has not been independently confirmed, security firms including Horizon3.ai and Picus Security have warned that the broader NetScaler vulnerability cluster is under active scanning and exploitation pressure, with comparisons drawn to the original CitrixBleed incident (Horizon3.ai, CSO Online). No specific threat actor attribution for CVE-2026-4368 has been publicly reported.

Exploitation steps

  1. Reconnaissance: Identify internet-facing NetScaler ADC or Gateway appliances configured in Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server mode using tools like Shodan or Censys, targeting versions prior to 14.1.66.54.
  2. Obtain low-privilege access: Acquire valid credentials for the target NetScaler environment (e.g., through phishing, credential stuffing, or use of a companion vulnerability such as CVE-2026-3055 to leak session tokens).
  3. Trigger concurrent session requests: Initiate a high volume of simultaneous authentication or session establishment requests to the Gateway or AAA virtual server endpoint, creating the timing conditions necessary for the race condition to manifest.
  4. Win the race condition: Time requests so that the appliance's session assignment logic incorrectly maps one user's session context to another, resulting in session mixup.
  5. Hijack victim session: Capture the misassigned session token or context, then use it to authenticate as the victim user, gaining access to their VPN session, internal resources, or data (Picus Security, Feedly).

Indicators of compromise

  • Network: Unusual spikes in concurrent authentication or session establishment requests to NetScaler Gateway or AAA virtual server endpoints; unexpected session tokens appearing from IP addresses inconsistent with the legitimate user's location.
  • Logs: NetScaler access logs showing multiple simultaneous login attempts from the same or different source IPs within very short time windows; session assignment anomalies in ns.log or /var/nslog/; users reporting being logged in as another user.
  • File System: No specific file artifacts are associated with this race condition vulnerability; focus on session and authentication log anomalies.
  • Process/Behavioral: Authenticated sessions accessing resources inconsistent with the user's role or permissions; duplicate active sessions for the same user account from different source IPs simultaneously (Picus Security, Defused Cyber).

Mitigation and workarounds

Citrix has released a patched version — NetScaler ADC and NetScaler Gateway 14.1.66.54 — which addresses CVE-2026-4368 along with CVE-2026-3055. Administrators should upgrade to this version or later immediately. No configuration-based workaround has been publicly documented for CVE-2026-4368 specifically; the recommended remediation is to apply the vendor patch without delay. Multiple national CERTs (UK NCSC, Canadian CCCS, EU CERT, Irish NCSC, Singapore CSA, Belgian CCB, New Zealand NCSC) have issued urgent advisories urging immediate patching (Citrix Advisory, UK NCSC, BleepingComputer).

Community reactions

Citrix/NetScaler urged administrators to patch "as soon as possible," and the disclosure generated significant coverage across the security community, with multiple comparisons to the original CitrixBleed (CVE-2023-4966) incident (BleepingComputer, IT Security Guru). The Hacker News, BleepingComputer, Security Affairs, Infosecurity Magazine, and CSO Online all covered the disclosure, with CSO Online noting expert comparisons to CitrixBleed 2 in severity (The Hacker News, CSO Online). Rapid7, Horizon3.ai, Picus Security, and Qualys published technical analyses, and national CERTs across Europe, North America, and Asia-Pacific issued urgent advisories. Community sentiment on social media (Mastodon, Bluesky, Reddit) reflected high concern given the history of NetScaler exploitation (Rapid7, Qualys).

Additional resources


SourceThis report was generated using AI

Related Citrix ADC VPX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8655HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-8452HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
YesYesJun 30, 2026
CVE-2026-8451HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-13474HIGH8.7
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-10817MEDIUM6.9
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management