Race condition in Citrix NetScaler Gateway and Citrix Netscaler ADC - CVE-2026-4368
Published: March 23, 2026
Vulnerability identifier: #VU124256
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-4368
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to a race condition. A remote user can exploit the race and compromise session of another user.
Successful exploitation of the vulnerability requires that the appliance is configured as Gateway or AAA virtual server.
Affected software
Citrix NetScaler Gateway
Citrix Netscaler ADC
Citrix Netscaler ADC
How to mitigate CVE-2026-4368
Install updates from vendor's website.
Citrix NetScaler Gateway - update to 14.1-66.54
Citrix Netscaler ADC - update to 14.1-66.54
Citrix Netscaler ADC - update to 14.1-66.54