CVE-2026-10817
published 2026-06-30CVE-2026-10817: Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.56%
44.8th percentile
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_application_delivery_controller | < 13.1-37.272 | 13.1-37.272 |
| citrix | netscaler_application_delivery_controller | — | — |
| citrix | netscaler_application_delivery_controller | >= 13.1 < 13.1-63.18 | 13.1-63.18 |
| citrix | netscaler_application_delivery_controller | >= 14.1 < 14.1-72.61 | 14.1-72.61 |
| citrix | netscaler_gateway | — | — |
| citrix | netscaler_gateway | >= 13.1 < 13.1-63.18 | 13.1-63.18 |
| citrix | netscaler_gateway | >= 14.1 < 14.1-72.61 | 14.1-72.61 |
| citrix | xenserver | — | — |
| netscaler | adc | >= 13.1 < 63.18 | 63.18 |
| netscaler | adc | >= 13.1 FIPS and NDcPP < 37.272 | 37.272 |
| netscaler | adc | >= 14.1 < 72.61 | 72.61 |
| netscaler | adc | >= 14.1 FIPS < 72.61 | 72.61 |
| netscaler | gateway | >= 13.1 < 63.18 | 63.18 |
| netscaler | gateway | >= 14.1 < 72.61 | 72.61 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Citrix NetScaler ADC/NetScaler Gateway prior 37.272/63.18/72.61 out-of-bounds (CTX696604)
vuldb·2026-06-30·CVSS 6.9
CVE-2026-10817 [MEDIUM] Citrix NetScaler ADC/NetScaler Gateway prior 37.272/63.18/72.61 out-of-bounds (CTX696604)
A vulnerability described as problematic has been identified in Citrix NetScaler ADC and NetScaler Gateway. Affected by this issue is some unknown functionality. Executing a manipulation can lead to out-of-bounds read.
This vulnerability appears as CVE-2026-10817. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
GHSA
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS
ghsa_unreviewed·2026-06-30
CVE-2026-10817 [MEDIUM] CWE-125 Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Citrix
Citrix Security Bulletin CTX696734
vendor_citrix·CVSS 7.5
CVE-2026-10816 [HIGH] Citrix Security Bulletin CTX696734
Citrix Security Bulletin CTX696734
CVE References: CVE-2026-10816, CVE-2026-10817, CVE-2026-13474, CVE-2026-3055, CVE-2026-42491, CVE-2026-4368, CVE-2026-53565, CVE-2026-53566, CVE-2026-8451, CVE-2026-8452, CVE-2026-8655
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
2026-06-30
Published