Database/Control plane, storage & DevOps
Citrix NetScaler ADC and Gateway: unauthenticated remote compromise of the appliance
Impact
Citrix describes only "a vulnerability" in NetScaler ADC and Gateway, but the scoring is unauthenticated, network-reachable, with high confidentiality, integrity and availability impact on the appliance and some spillover to systems behind it, and CISA lists it as exploited in the wild. Where NetScaler fronts a datacenter as the load balancer or the remote-access gateway, an attacker who takes it owns the TLS termination point, the session material for everyone logging in, and a foothold that sits between the internet and the cluster. Affected: ADC and Gateway 14.1 before 73.32 and 13.1 before 63.21. The record carries no technical detail at all - the mechanism, the affected feature and the preconditions are unknown from public data, so treat the exposure as broad until Citrix says otherwise.
Who can reach it
Network, unauthenticated, no user interaction per the CVSS 4.0 vector. The record does not say which virtual server type or feature must be configured, so assume any reachable NetScaler on an affected build is in scope.
What to do
Move to a fixed build per Citrix CTX696939 (14.1-73.32 or later, 13.1-63.21 or later on those branches). This is an appliance image upgrade and reboot rather than a package update: do it one HA node at a time and expect established sessions to drop. Given active exploitation, upgrading is not sufficient on its own - rotate credentials and session secrets the appliance held and review it for persistence, as Citrix has advised for prior exploited NetScaler flaws. Builds outside the two listed branches are end-of-life and get no fix.
References
Related entries
- Backpropagate (single-GPU LLM fine-tuning library) - Reflex web UI: The optional web UI exposes a training controlCVE-2026-48797 · Backpropagate (single-GPU LLM fine-tuning library) - Reflex web UICritical
- Assisted Migration Agent (hardcoded insecure TLS to vCenter): The agent hardcodes insecure TLS when talking to vCenterCVE-2026-53475 · Assisted Migration Agent (hardcoded insecure TLS to vCenter)Critical
- Linux liquidio driver (Marvell/Cavium, cached VF pci_dev lookup table): The LiquidIO PF caches VF `pci_dev` pointersCVE-2026-72329 · Linux liquidio driver (Marvell/Cavium, cached VF pci_dev lookup table)Critical
- Dell Secure Connect Gateway: exposed Docker socket gives a local user or container host rootCVE-2026-80238 · Dell Secure Connect Gateway 5.0 (orchestrator container / exposed Docker socket)Critical
- MinIO (OIDC authentication): JWT algorithm confusion in the OIDC login path lets an attacker present a token the serverCVE-2026-33322 · MinIO (OIDC authentication)Critical
- rclone (rc API, options/set): options/set is exposed pre-authentication and can rewrite the running instance's authCVE-2026-41176 · rclone (rc API, options/set)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.