INCIBE Warns of Six Citrix NetScaler Flaws
Spain’s national cybersecurity institute warned on July 3, 2026 about six vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
Spain’s National Cybersecurity Institute, INCIBE, issued an alert on July 3, 2026 for six vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, five classified as high severity and one as medium. According to the advisory, the attack vectors can lead to memory disclosure and denial of service, and Citrix recommends updating immediately because no effective mitigations have been documented.
INCIBE alert on NetScaler
Spain’s National Cybersecurity Institute, INCIBE, published an alert on July 3, 2026 for six vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. Five were classified as high severity and one as medium, according to the notice reproduced by Moncloa.com and INCIBE-CERT’s technical advisory.
The flaws can enable memory disclosure and denial of service. INCIBE-CERT also said they affect NetScaler devices exposed to the Internet, and that an unauthenticated remote attacker could trigger denial-of-service conditions and unauthorized access to information in memory, a particularly sensitive issue for environments that publish critical applications and support corporate remote access.
Affected versions and recommended patching
According to the alert, affected versions include NetScaler ADC and NetScaler Gateway 14.1 earlier than 14.1-72.61, 13.1 branches earlier than 13.1-63.18, FIPS editions of NetScaler ADC earlier than 14.1-72.61 FIPS, and NDcPP-compatible configurations earlier than 13.1-37.272.
Cited by INCIBE, Citrix recommends updating immediately to the fixed versions 14.1-72.61 for the 14.1 branch and 13.1-63.18 for the 13.1 branch, along with their FIPS and NDcPP equivalents. The company says patching is the only reliable way to neutralize the attack vectors described and that no effective workaround has been documented.
Investigation status
INCIBE said Citrix is still investigating whether these NetScaler vulnerabilities are being actively exploited. As of publication, however, no successful attack using them had been confirmed.
INCIBE-CERT’s official notice says the same and notes that there is still no known evidence of active exploitation. The technical advisory adds that organizations should coordinate with network and security teams to apply the fixed versions immediately and, after patching, verify that published services recover correctly.
Sources
- INCIBE alerta de seis vulnerabilidades en NetScaler ADC y Gateway de Citrixmoncloa.com· Moncloa.com
- Oracle EBS CVE-2026-46817: toma de control CVSS 9.8pasqualepillitteri.it· PasqualePillitteri.it
- Múltiples vulnerabilidades en NetScaler de Citrixincibe.es· INCIBE-CERT



