Who is affected
Citrix NetScaler ADC and Citrix NetScaler Gateway products are affected by a memory buffer boundary violation that can cause denial of service. The record does not specify which versions are vulnerable, which deployment modes are at risk, or whether the flaw requires authentication. You should assume both on-premises and cloud-hosted instances may be vulnerable until Citrix publishes version-specific guidance.
How to check whether this touches you
- Search your asset inventory for NetScaler ADC and NetScaler Gateway instances, including those operated by third parties on your behalf.
- Establish whether each instance is reachable from the internet or from untrusted networks; denial-of-service flaws are often exploitable remotely.
- Check Citrix's published advisories and security bulletins for the affected version range and any interim workarounds; version strings alone do not confirm whether a fix has been backported.
- If you run NetScaler in a cloud service, verify with your provider whether they have applied patches and ask for evidence of their patch timeline.
What to do
- Obtain the affected version range and available patch versions from Citrix immediately; do not rely on version numbers in this advisory.
- If you cannot patch within the federal remediation window (7 October 2026), apply network controls to restrict access to NetScaler instances from untrusted sources and document your justification.
- Enable detailed logging on NetScaler instances to capture connection attempts, errors, and resource exhaustion patterns that might indicate exploitation attempts.
- Plan your patch deployment in advance, including test environments and change-control procedures; memory safety flaws often require full service restart.
- If your organisation is unable to apply mitigations and no compensating controls are feasible, follow BOD 26-04 guidance on discontinuing use of the product.
If you find you were exposed
Exploitation of denial-of-service flaws often leaves sparse logs, because the goal is to crash or overload the service itself. Review NetScaler logs, system crash dumps, and upstream firewall or load-balancer records for evidence of unusual traffic patterns or repeated connection spikes in the weeks before the advisory date. Retention of at least 30 days of logs is essential; longer retention increases your chance of detecting compromise.