Cyber Cookie mascotCyber Cookie
Menu ▾
CVE-2026-10816
highCVSS 7.7

Citrix NetScaler ADC and NetScaler Gateway (versions prior to 14.1-72.61 and 13.1-63.18)

Citrix NetScaler products are network appliances used by organisations to manage, secure, and accelerate traffic flowing into their applications and services.

Reported in Issue #2381 Million Login Attempts and 78 Accounts Gone

Root Cause

The appliance fails to properly validate or restrict user-supplied input that controls which file path is accessed during a request. Because no authentication check gates this operation, the flaw is reachable by anyone who can reach the management interface.

Attack Vector

An attacker sends a crafted, unauthenticated HTTP request to the management interface, supplying a manipulated file path. The appliance processes it without validating who made the request or whether the path is permitted, and returns the contents of the targeted file. Configuration files and credentials are realistic targets.

Recommended Actions

  1. Upgrade to NetScaler ADC and Gateway 14.1-72.61 or 13.1-63.18 or later immediately.
  2. Restrict management interface access (NSIP/SNIP) to trusted internal networks only — never expose it to the public internet.
  3. Review access logs on the management interface for unexpected file-read requests from unfamiliar sources.