Dettaglio notizia

Data 01/07/2026
Titolo Citrix NetScaler Flaws Expose ADC and Gateway to Remote DoS and Memory Errors
Contesto Citrix published a security advisory for NetScaler ADC and NetScaler Gateway, warning that multiple high-severity vulnerabilities can be exploited remotely in specific deployments and configurations. The advisory, highlighted by the Canadian Centre for Cyber Security, affects the 14.1 and 13.1 release lines as well as certain NetScaler FIPS and NDcPP editions, and references six CVEs including CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, and CVE-2026-13474. Administrators were urged to review Citrix’s bulletin and move affected systems to fixed versions.

The disclosed flaws include a malformed HTTP/2 request issue that can trigger denial of service when HTTP/2 is enabled on affected LB, CS, VPN virtual servers or services (CVE-2026-13474); multiple memory overflow vulnerabilities tied to Oracle load balancer, DNS proxy, and DNS recursive resolver deployments (CVE-2026-8655); a memory overread caused by insufficient input validation when NetScaler is configured as a SAML Identity Provider (CVE-2026-8451); and a separate memory overflow vulnerability affecting Gateway or AAA virtual servers, including SSL VPN, ICA Proxy, CVPN, and RDP Proxy deployments (CVE-2026-8452). Recommended mitigations include applying Citrix security updates, disabling HTTP/2 or vulnerable Gateway features where not required, reviewing exposed virtual server and HTTP profile configurations, and monitoring for anomalous behavior.
Fonte https://mallory.ai/stories/019f1914-2f30-7f5f-9e51-43de4b987eb5
Discussione? Parliamone sul Forum