CVE-2026-4368 is a race condition vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway when configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, which can lead to user session mixup. Rated 7.7 HIGH, this flaw is remotely exploitable with low attack complexity and requires only low privileges, posing a high risk to confidentiality, integrity, and availability. While no public exploit code is currently available and it is not listed on CISA's KEV catalog, the vulnerability is receiving significant community attention, with experts noting its critical nature and potential severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| NetScaler | ADC | 14.1.66.54CNA affecteddefault unaffected | |
| NetScaler | Gateway | 14.1.66.54CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.