← Vulnerability feed

Vulnerability record · CVE-2026-8452 · published 30 June 2026

CVE-2026-8452: Citrix NetScaler ADC and Gateway memory buffer overflow causes DoS

Citrix · Netscaler Application Delivery Controller

CVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior and denial of service. It only affects appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, so exposure depends on that specific configuration.

8.8 CVSS 4.0 High CISA KEV since 26 Aug 2026 EPSS 1.0% · top 38.3% CWE-119 · Memory buffer overflow
8.8CVSS 4.0 base score
1.0%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
2References
27 Aug 2026Last modified by NVD

Description

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityThe flaw is remotely reachable without authentication or user interaction, causes denial of service, and is listed in CISA KEV with a short remediation deadline, indicating known exploitation.

What it is

CVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior and denial of service. It only affects appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, so exposure depends on that specific configuration.

Impact

An unauthenticated remote attacker can trigger a memory overflow that causes unpredictable behavior and denial of service on the affected appliance. The CVSS 4.0 vector also indicates high confidentiality impact, but the description does not state that code execution or data disclosure is confirmed.

Attack surface

Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N) per the CVSS 4.0 vector. Only appliances configured as a Gateway or AAA virtual server are affected.

Exploitation

CVE-2026-8452 was added to CISA KEV on 2026-08-26 with a remediation due date of 2026-08-29, indicating known exploitation; EPSS 30-day probability is 0.01606 (74.6th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Citrix vendor update referenced in advisory CTX696604 as the first action.
  • If patching is not immediately possible, follow CISA BOD 26-04 guidance and the vendor's mitigations, or discontinue use of the affected Gateway/AAA virtual server configuration.
  • Inventory NetScaler ADC and Gateway appliances and identify which are configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers.
  • Restrict network access to management and Gateway/AAA virtual server interfaces to trusted sources where operationally feasible.
  • Monitor Citrix and CISA advisories for updated guidance given the KEV listing.

Detection

  • Monitor NetScaler appliance logs and system events for crashes, restarts, or unexpected process terminations on Gateway and AAA virtual servers.
  • Alert on abnormal memory usage or resource exhaustion on NetScaler ADC/Gateway instances.
  • Review network traffic to Gateway and AAA virtual server endpoints for anomalous or malformed requests preceding service disruption.
  • Track availability of the Gateway/AAA virtual server and investigate unexplained outages as potential exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-8452 to the Known Exploited Vulnerabilities catalog on 26 August 2026 as "Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 29 August 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-8452 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-3519Citrix NetScaler ADC and Gateway unauthenticated code injectionCitrix NetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that allows unauthenticated remote code execution. The vendor bulle…KEVEPSS 100%analysed9.3CVE-2026-19490Citrix NetScaler ADC and Gateway authentication bypass via alternate pathNetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel (CWE-288). The flaw is remotely reachable witho…KEVEPSS 7.0%analysed9.3CVE-2026-3055Citrix NetScaler ADC and Gateway SAML IDP memory overreadNetScaler ADC and NetScaler Gateway, when configured as a SAML identity provider, fail to validate input sufficiently, causing an out-of-bounds memor…KEVEPSS 4.0%analysed9.3CVE-2025-5777Citrix NetScaler ADC/Gateway memory overread via insufficient input validationCVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance…KEVEPSS 100%analysed9.2CVE-2025-7775Citrix NetScaler memory overflow allows remote code executionNetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that can lead to remote code execution or denial of service. It affect…KEVEPSS 20%analysed9.2CVE-2025-6543Citrix NetScaler ADC and Gateway memory overflow allows control flow hijack and DoSNetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that causes unintended control flow and denial of service. It affects …KEVEPSS 11%analysed8.8CVE-2023-6548Citrix NetScaler ADC and Gateway code injection enables low-privileged RCENetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that lets an attacker with access to an NSIP, CLIP or SNIP management inte…KEVEPSS 3.2%analysed7.5CVE-2023-6549Citrix NetScaler ADC and Gateway out-of-bounds memory read and DoSNetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer (CWE-119), allowing an out-of-…KEVEPSS 58%analysed

Source: NIST National Vulnerability Database (record CVE-2026-8452), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.