Citrix patches 6 NetScaler flaws: file-read and DoS risks

Citrix has updated NetScaler ADC and NetScaler Gateway, fixing six vulnerabilities, including risks of file read and denial of service.
Some issues affect SAML IDP, Gateway/AAA, DNS/LB scenarios, and HTTP/2. For one flaw, a patch alone is not enough: if HTTP Strict Profiles are not used, set Http2SmallWndTimeout to 30 seconds in the HTTP profile.
There is no sign of active exploitation yet, but perimeter software like this demands rapid response.
Citrix often sits at critical access points, so delay can increase the risk of data leakage and downtime.
Have you checked your NetScaler versions and configurations?

