Memory Overflow Vulnerability in NetScaler ADC and Gateway by Citrix
CVE-2026-8452
Key Information:
Badges
What is CVE-2026-8452?
CVE-2026-8452 is a memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway systems developed by Citrix. These products serve as application delivery controllers, optimizing the performance and security of web applications and providing secure remote access for users. The vulnerability can lead to unpredictable or erroneous behavior of the appliances, particularly when configured as a Gateway or AAA virtual server. In such scenarios, a successful exploit may result in the Denial of Service (DoS), severely impacting organizational access to critical services and applications.
Potential Impact of CVE-2026-8452
-
Denial of Service: The primary concern surrounding this vulnerability is its potential to cause DoS, rendering vital services inaccessible to legitimate users. This can lead to operational disruptions and hinder business continuity.
-
Unpredictable Behavior: The memory overflow can instigate erratic system behavior, which not only compromises the performance of application delivery mechanisms but also poses significant risks for system stability and reliability.
-
Increased Attack Surface: By allowing exploitation avenues within configured Gateways, the vulnerability can widen the attack surface for threat actors, prompting concerns regarding overall network security and the possibility of further compromises in the broader infrastructure.
CISA has reported CVE-2026-8452
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-8452 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
ADC 14.1 < 72.61
ADC 13.1 < 63.18
ADC 14.1 FIPS < 72.61
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
CISA Warns of Citrix NetScaler ADC and Gateway Vulnerability Exploited in Attacks
CISA added critical Citrix NetScaler flaw CVE-2026-8452 to its KEV catalog after confirming exploitation.
4 days ago

Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) - IT Security News
2026-08-27 12:08 CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as...
4 days ago
Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) - Help Net Security
Citrix NetScaler ADC and Gateway flaw CVE-2026-8452 is under active attack, with hackers dropping web shells days after a public PoC.
4 days ago
References
CVSS V4
Timeline
- 🦅
CISA Reported
- 🥇
Vulnerability reached the number 1 worldwide trending spot
- 🟡
Public PoC available
- 👾
Exploit known to exist
- 📈
Vulnerability started trending
- 📰
First article discovered by Cybersecuritynews
Vulnerability published
Vulnerability Reserved