CVE-2026-10817EPSS p34.1%
CVE-2026-10817CVE-2026-10817
citrix / netscaler_application_delivery_controller
Description
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 0.41% probability of exploitation · percentile 34.1% · 2026-08-14T12:00:27Z |
| Last modified | 2026-07-02 |