SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAwaiting Analysis

CVE-2026-4368

Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup

HIGH 7.7EPSS 3.62%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup

CVSS 4.0
7.7 HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
3.62% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-362
Source
50a63c94-1ea7-4568-8c11-eb79e7c5a2b5

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.