External Control of File Name or Path in Citrix Netscaler ADC and Citrix NetScaler Gateway - CVE-2026-10816
Published: June 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to external control of file name or path in the management interface when handling file access requests. A remote attacker can request arbitrary files to disclose sensitive information.
Exploitation requires access to NSIP, Cluster Management IP, or SNIP with management access enabled.
Affected software
Citrix NetScaler Gateway
How to mitigate CVE-2026-10816
Citrix NetScaler Gateway - addressed in versions 13.1-63.18, 14.1-72.61