Back Heise.De Attackers can disable Citrix NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway are vulnerable, and attackers can bring instances to a standstill using DoS attacks. This can make important network areas in companies unreachable, among other things. Security updates are available for download. So far, there are no indications that attackers are already exploiting the vulnerabilities.
The software company points out that the cloud instances have already been patched. Admins who host instances themselves must act.
Except one security vulnerability (CVE-2026-10817 “ medium ”), all others (CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, 13474) are classified as “ high ” threat level. In all cases, certain prerequisites must be met for attacks to be possible at all. The developers provide these and further information in a warning message here.
In one case, the Single Sign-On component SAML IDP must be active, for example. If this is the case, attackers can trigger a memory error in an unspecified way. In such a context, malicious code execution often occurs, leading to a complete compromise of systems.
The DoS attacks also stem from memory errors and can cause services to crash. For this to work, NetScaler ADC must be configured as a DNS proxy, for example. In another case, prepared HTTP/2 requests can cause problems and trigger crashes. However, the HTTP/2 profile must be activated beforehand. Attackers can also gain unauthorized access to files and read them.
To prevent such attacks, administrators must install one of the following versions: All releases are vulnerable.
Most recently, Citrix made headlines at the end of March with attacks on Gateway and NetScaler ADC here.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
