Race condition in Citrix NetScaler Gateway and Citrix Netscaler ADC - CVE-2026-4368

 

Race condition in Citrix NetScaler Gateway and Citrix Netscaler ADC - CVE-2026-4368

Published: March 23, 2026


Vulnerability identifier: #VU124256
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-4368
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to a race condition. A remote user can exploit the race and compromise session of another user.

Successful exploitation of the vulnerability requires that the appliance is configured as Gateway or AAA virtual server. 


Affected software

Citrix NetScaler Gateway
Citrix Netscaler ADC

How to mitigate CVE-2026-4368

Install updates from vendor's website.

Citrix NetScaler Gateway - update to 14.1-66.54
Citrix Netscaler ADC - update to 14.1-66.54

External References

Related Security Bulletins