PT-2026-27202 · Citrix · Netscaler Adc+1
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
NetScaler ADC versions prior to 14.1-60.58
NetScaler Gateway versions prior to 13.1-662.23
Description
Insufficient input validation in the SAML processing module of NetScaler ADC and NetScaler Gateway, when configured as a SAML Identity Provider (IdP), allows an unauthenticated remote attacker to trigger an out-of-bounds memory read. By sending specially crafted SAML authentication requests with a malformed
AttributeValue length, an attacker can cause the parser to read past the input buffer into the system heap memory. This memory leak can expose sensitive data, including active session tokens, administrative credentials, plaintext cookies, and private cryptographic keys, potentially allowing attackers to bypass Multi-Factor Authentication (MFA) and hijack live user sessions. Approximately 30,000 NetScaler instances are estimated to be internet-exposed globally. Real-world exploitation has been observed, including reconnaissance and active attacks by the threat actor MuddyWater.Recommendations
Update NetScaler ADC to version 14.1-60.58 or later.
Update NetScaler Gateway to version 13.1-662.23 or later.
Perform a full reboot of the appliance after patching to clear the memory space.
Terminate all active user sessions to invalidate potentially stolen tokens.
Use the
flush cache command to remove malicious SAML data.
Rotate private keys used for SAML signing if a breach is suspected.
As a temporary mitigation, restrict access to the SAML IdP functionality if it is not critical for operations.Exploit
Fix
RCE
LPE
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netscaler Adc
Netscaler Gateway