Arbitrary File Read Vulnerability in NetScaler ADC and Gateway by Citrix
CVE-2026-10816

7.1HIGH

Key Information:

Vendor

Netscaler

Vendor
CVE Published:
30 June 2026

What is CVE-2026-10816?

An arbitrary file read vulnerability exists in Citrix NetScaler ADC and NetScaler Gateway due to enabled management access to the NSIP, Cluster Management IP, or SNIP. This issue allows unauthenticated users to read sensitive files, potentially exposing critical system information. Organizations using these products should ensure that management access is properly restricted to minimize the risk from this vulnerability.

Affected Version(s)

ADC 14.1 < 72.61

ADC 13.1 < 63.18

ADC 14.1 FIPS < 72.61

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.