Citrix security advisory (AV26-645) – Update 1

Serial number: AV26-645
Date: June 30, 2026
Updated: July 2, 2026

On June 30, 2026, Citrix published a security advisory to address critical vulnerabilities in the following products:

  • NetScaler ADC and NetScaler Gateway - versions 14.1 before 14.1-72.61
  • NetScaler ADC and NetScaler Gateway - versions 13.1 before 13.1-63.18
  • NetScaler ADC FIPS – versions before 14.1-72.61 FIPS
  • NetScaler ADC FIPS and NDcPP – versions before 13.1-37.272

Update 1

Open-source reporting indicates that CVE-2026-8451 is being exploited.

The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.

Date modified: