Overview
What is CVE-2026-4368?
Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup
Vulnerability intelligence
CVE-2026-4368 and is rated High severity with a CVSS score of 7.7. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup