CVE-2026-10817 PUBLISHED

Insufficient input validation leading to memory overread

Assigner: NetScaler
Reserved: 04.06.2026 Published: 30.06.2026 Updated: 30.06.2026

Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor NetScaler
Product ADC
Versions Default: unaffected
  • affected from 14.1 to 72.61 (excl.)
  • affected from 13.1 to 63.18 (excl.)
  • affected from 14.1 FIPS to 72.61 (excl.)
  • affected from 13.1 FIPS and NDcPP to 37.272 (excl.)
Vendor NetScaler
Product Gateway
Versions Default: unaffected
  • affected from 14.1 to 72.61 (excl.)
  • affected from 13.1 to 63.18 (excl.)

References

Problem Types

  • CWE-125 Out-of-bounds read CWE