Skip to content
Critical security vulnerability in Citrix Gateway and Netscaler ADC

Critical security vulnerability in Citrix Gateway and Netscaler ADC

Heise.De March 23, 2026

The manufacturer "Cloud Software Group" has fixed two security vulnerabilities in the Citrix products "Netscaler ADC" (Application Delivery Controller) and "Gateway", one of them with a critical rating. The errors were noticed during an internal review, and updates have already been released. Citrix customers should quickly check if they are affected and update their appliances.

The two security vulnerabilities in detail:

The discerning reader of the Citrix security advisory must for details with a magnifying glass, but some details are reminiscent of the fatal security vulnerability CitrixBleed 2 from 2025. This also consisted of a memory leak that remote attackers could exploit to intercept access tokens. In conjunction with the now additionally reported race condition, they could use this specifically to take over certain user accounts.

Admins should quickly update to the updated versions:

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities

Attack Types (1)

Platforms (2)

Vulnerabilities (1)