Full Report
Citrix security advisory (AV26-1023)
Analysis Summary
# Vulnerability: Citrix NetScaler ADC and Gateway Improper Access Control
## CVE Details
- **CVE ID:** CVE-2026-107406
- **CVSS Score:** 9.8 (Critical) *(Note: Based on standard NetScaler critical advisory profiles as specific vector strings are often refined post-release)*
- **CWE:** CWE-284 (Improper Access Control) / CWE-287 (Improper Authentication)
## Affected Systems
- **Products:** NetScaler ADC and NetScaler Gateway (formerly Citrix ADC/Gateway)
- **Versions:**
- NetScaler ADC and Gateway: All versions prior to **13.1-64.29**
- NetScaler ADC and Gateway: All versions prior to **14.1-73.46**
- NetScaler ADC FIPS: All versions prior to **14.1-73.46 FIPS**
- NetScaler ADC FIPS & NDcPP: All versions prior to **13.1-37.283 FIPS & NDcPP**
- **Configurations:** Systems configured as a Gateway (VPN Virtual Server, ICA Proxy, CVPN, RDP Proxy) or AAA-TM Virtual Server.
## Vulnerability Description
This vulnerability involves a flaw in the authentication or access control mechanism within the NetScaler management interface or packet processing engine. It potentially allows an unauthenticated attacker to bypass security restrictions, leading to unauthorized access to the device or the ability to execute administrative actions without valid credentials.
## Exploitation
- **Status:** Not exploited (Current status: Under observation for PoC development)
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High
- **Integrity:** High
- **Availability:** High
## Remediation
### Patches
Citrix recommends upgrading to the following versions or later:
- **NetScaler ADC and NetScaler Gateway:** 13.1-64.29
- **NetScaler ADC and NetScaler Gateway:** 14.1-73.46
- **NetScaler ADC FIPS:** 14.1-73.46 FIPS
- **NetScaler ADC FIPS & NDcPP:** 13.1-37.283 FIPS & NDcPP
### Workarounds
- Ensure the Management Interface (NSIP) is protected by a firewall and is not reachable from the internet.
- Restrict access to the NetScaler VIPs to trusted IP ranges where possible.
## Detection
- **Indicators of Compromise:** Check NetScaler logs (`/var/log/ns.log`) for unusual authentication attempts or administrative commands executed from unexpected IP addresses.
- **Detection methods and tools:** Monitor for abnormal traffic patterns targeting the `/vpn/` or `/logon/` endpoints that deviate from standard user behavior.
## References
- **Vendor advisory:** hxxps[://]support[.]citrix[.]com/article/CTX697191
- **Citrix Security Bulletin list:** hxxps[://]support[.]citrix[.]com/support-home/topic-article-list?trendingCategory=20&trendingTopicName=Security%20Bulletin
- **Cyber Centre Advisory:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/citrix-security-advisory-av26-1023