Threat Intelligence / CVE / CVE-2026-4368

CVE-2026-4368 — Citrix Netscaler Adc

CVSS v4.0 7.7 (HIGH) · EPSS 0.0% (higher than 4.1% of all scored CVEs) · Priority 4/10 · Published 2026-03-23

As of 2026-03-24, CVE-2026-4368 is a HIGH-severity vulnerability in Citrix Netscaler Adc, CVSS v4.0 7.7, EPSS 0.0% (4.1th percentile). Threadlinqs Intelligence links 4 tracked threat campaigns to CVE-2026-4368, most recently “CitrixBleed 2.0: CVE-2026-8451 NetScaler SAML IDP Memory Overread Under Active Exploitation”.

Last updated: 2026-03-24

What is CVE-2026-4368?

Race condition vulnerability (CWE-362) in Citrix NetScaler ADC and NetScaler Gateway when configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Under specific timing conditions during concurrent user authentication, the race condition causes one user's authenticated session context to be incorrectly associated with another user, enabling session hijacking and unauthorized access to another user's resources. Disclosed alongside CVE-2026-3055 (pre-auth memory overread, CVSS 9.3) in Citrix security bulletin CTX696300 on March 23, 2026. Only affects build 14.1-66.54 specifically and requires low privileges and precise timing to exploit. Part of the CitrixBleed vulnerability family — predecessors CVE-2023-4966 and CVE-2025-5777 saw rapid weaponization by ransomware groups including LockBit and APT Salt Typhoon. Shadowserver reports over 30,000 NetScaler ADC instances exposed to the internet. Patched in versions 14.1-66.59, 13.1-62.23, and 13.1-37.262 (FIPS/NDcPP). Cloud-managed instances are not affected.

The record classifies CVE-2026-4368 under weakness class CWE-362. 2 affected-product entries are recorded, across 1 vendor, listed below. The identifier was first published 174 days ago.

Severity and exploitation probability

CVSS v4.0 base score
7.7
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS (FIRST)
0.0% probability of exploitation in the next 30 days, higher than 4.1% of all scored CVEs
CISA KEV
Not listed in the CISA Known Exploited Vulnerabilities catalog
Threadlinqs priority
4/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
Published
2026-03-23, last modified 2026-03-24

Is CVE-2026-4368 being exploited?

It currently carries a trending score of 11 in the Threadlinqs vulnerability feed.

Affected products and versions

How to fix CVE-2026-4368

The record marks a vendor fix as available for CVE-2026-4368. Patch reference: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300. Vendor advisory: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.

Threat activity tracking CVE-2026-4368

4 tracked threats in the Threadlinqs corpus reference CVE-2026-4368, either in the campaign’s CVE list or as an indicator on the campaign record.

Sources

Seeded from threat-derived and not yet processed by the Threadlinqs enrichment pipeline, so blank CVSS, EPSS or KEV fields above mean NOT MEASURED rather than measured-absent.

Full detection coverage & IOCs for threats exploiting CVE-2026-4368 are available via the Threadlinqs MCP server (Purple tier). View plans →

← all vulnerabilities · Markdown version · Threadlinqs Intelligence