Vulnerability record · CVE-2026-8452 · published 30 June 2026
CVE-2026-8452: Citrix NetScaler ADC and Gateway memory buffer overflow causes DoS
Citrix · Netscaler Application Delivery Controller
CVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior and denial of service. It only affects appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, so exposure depends on that specific configuration.
Description
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityThe flaw is remotely reachable without authentication or user interaction, causes denial of service, and is listed in CISA KEV with a short remediation deadline, indicating known exploitation.
What it is
CVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior and denial of service. It only affects appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, so exposure depends on that specific configuration.
Impact
An unauthenticated remote attacker can trigger a memory overflow that causes unpredictable behavior and denial of service on the affected appliance. The CVSS 4.0 vector also indicates high confidentiality impact, but the description does not state that code execution or data disclosure is confirmed.
Attack surface
Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N) per the CVSS 4.0 vector. Only appliances configured as a Gateway or AAA virtual server are affected.
Exploitation
CVE-2026-8452 was added to CISA KEV on 2026-08-26 with a remediation due date of 2026-08-29, indicating known exploitation; EPSS 30-day probability is 0.01606 (74.6th percentile). No ransomware campaign use is documented.
What to do
- Apply the Citrix vendor update referenced in advisory CTX696604 as the first action.
- If patching is not immediately possible, follow CISA BOD 26-04 guidance and the vendor's mitigations, or discontinue use of the affected Gateway/AAA virtual server configuration.
- Inventory NetScaler ADC and Gateway appliances and identify which are configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers.
- Restrict network access to management and Gateway/AAA virtual server interfaces to trusted sources where operationally feasible.
- Monitor Citrix and CISA advisories for updated guidance given the KEV listing.
Detection
- Monitor NetScaler appliance logs and system events for crashes, restarts, or unexpected process terminations on Gateway and AAA virtual servers.
- Alert on abnormal memory usage or resource exhaustion on NetScaler ADC/Gateway instances.
- Review network traffic to Gateway and AAA virtual server endpoints for anomalous or malformed requests preceding service disruption.
- Track availability of the Gateway/AAA virtual server and investigate unexplained outages as potential exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-8452 to the Known Exploited Vulnerabilities catalog on 26 August 2026 as "Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 29 August 2026.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8452 | US Government Resource |
Track CVE-2026-8452 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-8452), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.