Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > Citrix
#Citrix

Critical NetScaler Memory Flaw Exposes SAML Appliances to Remote Code Execution

9 October 2026  |  dark6  |  Vulnerability

Citrix has released urgent updates for a critical NetScaler ADC and Gateway memory-overflow vulnerability with a CVSS 9.5 rating. Exposure depends on the appliance build and whether it...

>> read more

Patched Citrix NetScaler Appliances Are Crashing on Their Own, and Nobody’s Sure Why Yet

5 October 2026  |  dark6  |  Vulnerability

Citrix customers who rushed to install the emergency 14.1-73.37 build for two actively exploited NetScaler zero-days are now reporting repeated appliance reboots triggered by malformed SAML traffic. Citrix...

>> read more

Two Reported NetScaler Zero-Days Put Internet-Facing Gateways on Emergency Watch

28 September 2026  |  dark6  |  Vulnerability

Researchers say two undisclosed Citrix NetScaler remote-code-execution flaws are already being used in attacks, although vendor confirmation and technical indicators remain pending. Defenders should inventory exposed appliances, preserve...

>> read more

Citrix Patches Critical NetScaler Flaw That Lets Attackers Skip the Login Screen Entirely

20 August 2026  |  dark6  |  Vulnerability

Citrix has patched two new NetScaler ADC and Gateway vulnerabilities, including a 9.3-severity authentication bypass that can let remote attackers slip past login controls on SSL VPN, ICA...

>> read more

Citrix NetScaler Root-Level RCE Flaw Goes Public With Working Exploit Code

15 August 2026  |  dark6  |  Vulnerability

A publicly released proof-of-concept shows how a pre-authentication heap overflow in Citrix NetScaler ADC and Gateway can be turned into unauthenticated, root-level remote code execution. There is no...

>> read more

Citrix Patches Privilege Escalation Flaw That Hands Standard Users Full SYSTEM Control

19 July 2026  |  dark6  |  Vulnerability

Cloud Software Group has disclosed two vulnerabilities in Citrix Secure Access and Endpoint Analysis clients for Windows, including a high-severity flaw (CVSS 8.5) that lets a low-privileged local...

>> read more