PT-2026-53867 · Citrix · Netscaler Gateway+1
Published
2026-06-30
·
Updated
2026-06-30
·
CVE-2026-10817
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NetScaler ADC (affected versions not specified)
NetScaler Gateway (affected versions not specified)
Description
Insufficient input validation leads to a memory overread when the TCP TimeStamp is enabled in the TCP Profile and is associated with a service or a virtual server of type LB, CS, or VPN. A memory overread occurs when a program reads data past the end of the intended buffer, potentially exposing sensitive information from the system memory.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, disable the TCP TimeStamp in the TCP Profile associated with the virtual server or service.
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netscaler Adc
Netscaler Gateway