SB2026032373 - Race condition in Citrix Netscaler ADC and Citrix NetScaler Gateway
Published: March 23, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Race condition (CVE-ID: CVE-2026-4368)
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to a race condition. A remote user can exploit the race and compromise session of another user.
Successful exploitation of the vulnerability requires that the appliance is configured as Gateway or AAA virtual server.
Remediation
Install update from vendor's website.