CVE-2026-10816
published 2026-06-30CVE-2026-10816: Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is…
PriorityP353high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.58%
45.7th percentile
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_application_delivery_controller | < 13.1-37.272 | 13.1-37.272 |
| citrix | netscaler_application_delivery_controller | — | — |
| citrix | netscaler_application_delivery_controller | >= 13.1 < 13.1-63.18 | 13.1-63.18 |
| citrix | netscaler_application_delivery_controller | >= 14.1 < 14.1-72.61 | 14.1-72.61 |
| citrix | netscaler_gateway | — | — |
| citrix | netscaler_gateway | >= 13.1 < 13.1-63.18 | 13.1-63.18 |
| citrix | netscaler_gateway | >= 14.1 < 14.1-72.61 | 14.1-72.61 |
| citrix | xenserver | — | — |
| netscaler | adc | >= 13.1 < 63.18 | 63.18 |
| netscaler | adc | >= 13.1 FIPS and NDcPP < 37.272 | 37.272 |
| netscaler | adc | >= 14.1 < 72.61 | 72.61 |
| netscaler | adc | >= 14.1 FIPS < 72.61 | 72.61 |
| netscaler | gateway | >= 13.1 < 63.18 | 63.18 |
| netscaler | gateway | >= 14.1 < 72.61 | 72.61 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.07.1HIGHCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Citrix NetScaler ADC/NetScaler Gateway file inclusion (CTX696604)
vuldb·2026-06-30·CVSS 7.1
CVE-2026-10816 [HIGH] Citrix NetScaler ADC/NetScaler Gateway file inclusion (CTX696604)
A vulnerability classified as critical was found in Citrix NetScaler ADC and NetScaler Gateway. The affected element is an unknown function. Such manipulation leads to file inclusion.
This vulnerability is traded as CVE-2026-10816. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is advised.
GHSA
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
ghsa_unreviewed·2026-06-30
CVE-2026-10816 [HIGH] CWE-73 Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
Citrix
Citrix Security Bulletin CTX696734
vendor_citrix·CVSS 7.5
CVE-2026-10816 [HIGH] Citrix Security Bulletin CTX696734
Citrix Security Bulletin CTX696734
CVE References: CVE-2026-10816, CVE-2026-10817, CVE-2026-13474, CVE-2026-3055, CVE-2026-42491, CVE-2026-4368, CVE-2026-53565, CVE-2026-53566, CVE-2026-8451, CVE-2026-8452, CVE-2026-8655
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
2026-06-30
Published