CVE-2018-17446: Citrix NetScaler SD-WAN

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

Affected products

  • Citrix NetScaler SD-WAN: from 9.3.0, up to and including 9.3.6; from 10.0.0, up to and including 10.0.4
  • Citrix SD-WAN: version 10.1.0 only

Published 2018-10-23. Last modified 2026-06-17.