imPC@ndo IT

Tracker / CVE-2026-10817

CVE-2026-10817

High 7.5

Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler

Affected products and versions

citrix netscaler_application_delivery_controller
citrix netscaler_application_delivery_controller · … → 13.1-37.272
citrix netscaler_application_delivery_controller · 13.1 → 13.1-63.18
citrix netscaler_application_delivery_controller · 14.1 → 14.1-72.61
citrix netscaler_gateway · 13.1 → 13.1-63.18
citrix netscaler_gateway · 14.1 → 14.1-72.61

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References