CVE-2026-10817: Insufficient input validation leading to memory overread
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If TCP TimeStamp is enabled in the TCP Profile and associated with a virtual server (LB, CS, VPN) or a service on NetScaler, disable TCP TimeStamp to mitigate insufficient input validation leading to memory overread.
NetScaler ADC / NetScaler Gateway TCP TimeStamp (TCP Profile) = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10817?
The severity of CVE-2026-10817 is rated at 65.
How do I fix CVE-2026-10817?
To fix CVE-2026-10817, ensure that TCP TimeStamp is disabled in the TCP Profile associated with your virtual server or service.
What systems are affected by CVE-2026-10817?
CVE-2026-10817 affects Citrix NetScaler ADC and Citrix NetScaler Gateway if specific conditions are met.
What does CVE-2026-10817 exploit?
CVE-2026-10817 exploits insufficient input validation leading to memory overread.
What configuration should I check for CVE-2026-10817?
For CVE-2026-10817, check the TCP Profile settings to see if TCP TimeStamp is enabled.