HIGH
Insufficient input validation leading to memory overread
Published Jun 30, 2026
8.8
HIGHCVSS 4.0
EPSS 0.50%
Description
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
Affected products
-
- Version 13.1StatusaffectedConstraints<63.18
- Version 13.1 FIPS and NDcPPStatusaffectedConstraints<37.272
- Version 14.1StatusaffectedConstraints<72.61
- Version 14.1 FIPsStatusaffectedConstraints<72.61
- Version
-
- Version 13.1StatusaffectedConstraints<63.18
- Version 14.1StatusaffectedConstraints<72.61
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
OR
- < 13.1-37.272
- < 13.1-37.272
- ≥ 13.1 · < 13.1-63.18
- ≥ 14.1 · < 14.1-72.61
- 14.1-66.68
- ≥ 13.1 · < 13.1-63.18
- ≥ 14.1 · < 14.1-72.61
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40305 Advisory
- https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-40305 | Advisory | |
| https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner NetScaler
Published Jun 30, 2026
Updated Jun 30, 2026
Reserved May 13, 2026
Link CVE-2026-8451
CISA Vulnrichment
Updated Jun 30, 2026
ENISA EUVD
EUVD-2026-40305 Assigner NetScaler
Published Jun 30, 2026
Updated Jun 30, 2026
Exploited since n/a
Link EUVD-2026-40305