CVE-2026-4368 PUBLISHED

Race Condition leading to User Session Mixup

Assigner: NetScaler
Reserved: 18.03.2026 Published: 23.03.2026 Updated: 24.03.2026

Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.7

Product Status

Vendor NetScaler
Product ADC
Versions Default: unaffected
  • Version 14.1.66.54 is affected
Vendor NetScaler
Product Gateway
Versions Default: unaffected
  • Version 14.1.66.54 is affected

References