PT-2026-53867 · Citrix · Netscaler Gateway+1

Published

2026-06-30

·

Updated

2026-06-30

·

CVE-2026-10817

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NetScaler ADC (affected versions not specified) NetScaler Gateway (affected versions not specified)
Description Insufficient input validation leads to a memory overread when the TCP TimeStamp is enabled in the TCP Profile and is associated with a service or a virtual server of type LB, CS, or VPN. A memory overread occurs when a program reads data past the end of the intended buffer, potentially exposing sensitive information from the system memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary mitigation, disable the TCP TimeStamp in the TCP Profile associated with the virtual server or service.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10817

Affected Products

Netscaler Adc
Netscaler Gateway