CVE-2026-4368 Details
Description
Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup
A race condition vulnerability has been identified in Citrix NetScaler ADC and NetScaler Gateway, specifically in version 14.1-66.54. When the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, this vulnerability can lead to a mix-up of user sessions.
Affected customers are advised to upgrade to NetScaler ADC and NetScaler Gateway versions 14.1-66.59 or later, 13.1-62.23 or later, or for NetScaler ADC 13.1-FIPS and 13.1-NDcPP, version 13.1.37.262 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300 | NetScaler |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | NetScaler |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 10, 2026 | CVE Modified | CISA-ADP |
| Mar 23, 2026 | New CVE Received | NetScaler |