Citrix Security Updates – 01 July 2026

Citrix has released security updates to address several vulnerabilities affecting Citrix XenServer, Citrix NetScaler ADC, and Citrix NetScaler Gateway.

The addressed vulnerabilities could allow the attacker to conduct denial of service attacks, trigger memory corruption, obtain sensitive information, or execute arbitrary code, and gain unauthorized access to the affected systems.

Sample of the addressed vulnerabilities:

1. Insufficient Input Validation in NetScaler ADC and NetScaler Gateway Vulnerability (CVE-2026-8451):

  • CVSS 4.0: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Attack Requirements: None
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Obtain Information

2. Race Condition in NetScaler ADC and NetScaler Gateway Vulnerability (CVE- 2026-8452):

  • CVSS 4.0: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Attack Requirements: None
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service
Vulnerabilities
  • CVE-2026-8451
  • CVE-2026-8452
  • CVE-2026-8655
  • CVE-2026-10816
  • CVE-2026-10817
  • CVE-2026-13474
  • CVE-2026-23556
  • CVE-2026-23558
  • CVE-2026-23559
  • CVE-2026-23560
  • CVE-2026-23561
  • CVE-2025-54505
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed. 

Citrix Security Updates

References