CVE-2026-8452
published 2026-06-30CVE-2026-8452: Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is…
PriorityP187critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-08-29
Exploited in the wild
EPSS
1.61%
74.4th percentile
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_application_delivery_controller | < 13.1-37.272 | 13.1-37.272 |
| citrix | netscaler_application_delivery_controller | — | — |
| citrix | netscaler_application_delivery_controller | >= 13.1 < 13.1-63.18 | 13.1-63.18 |
| citrix | netscaler_application_delivery_controller | >= 14.1 < 14.1-72.61 | 14.1-72.61 |
| citrix | netscaler_gateway | — | — |
| citrix | netscaler_gateway | >= 13.1 < 13.1-63.18 | 13.1-63.18 |
| citrix | netscaler_gateway | >= 14.1 < 14.1-72.61 | 14.1-72.61 |
| citrix | xenserver | — | — |
| netscaler | adc | >= 13.1 < 63.18 | 63.18 |
| netscaler | adc | >= 13.1 FIPS and NDcPP < 37.272 | 37.272 |
| netscaler | adc | >= 14.1 < 72.61 | 72.61 |
| netscaler | adc | >= 14.1 FIPS < 72.61 | 72.61 |
| netscaler | gateway | >= 13.1 < 63.18 | 63.18 |
| netscaler | gateway | >= 14.1 < 72.61 | 72.61 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat4.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy,
ghsa_unreviewed·2026-06-30
CVE-2026-8452 [HIGH] CWE-119 Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy,
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
VulDB
Citrix NetScaler ADC/NetScaler Gateway Virtual Server Page denial of service (CTX696604 / EUVD-2026-40307)
vuldb·2026-06-30·CVSS 8.8
CVE-2026-8452 [HIGH] Citrix NetScaler ADC/NetScaler Gateway Virtual Server Page denial of service (CTX696604 / EUVD-2026-40307)
A vulnerability has been found in Citrix NetScaler ADC and NetScaler Gateway and classified as problematic. The affected element is an unknown function of the component Virtual Server Page. Performing a manipulation results in denial of service.
This vulnerability was named CVE-2026-8452. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
VulnCheck
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2026·CVSS 9.8
CVE-2026-8452 [CRITICAL] Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
Affected: Citrix NetScaler ADC and NetScaler Gateway
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://kevintel.com/CVE-2026-8452; https://www.linkedin.com/posts/this-morning-we-started-seeing-exploitation-share-7495030099205988353-6TYd/; https://x.com/DefusedCyber/status/2089304576759415270
Exploit P
CISA
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
cisa·2026-08-26·CVSS 9.8
CVE-2026-8452 [CRITICAL] CWE-119 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Vulnerability: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Affected: Citrix NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each
Citrix
Citrix Security Bulletin CTX696604
vendor_citrix·CVSS 8.8
CVE-2025-5349 [HIGH] Citrix Security Bulletin CTX696604
Citrix Security Bulletin CTX696604
CVE References: CVE-2025-5349, CVE-2025-5777, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397, CVE-2026-8451, CVE-2026-8452, CVE-2026-8655
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX696734
vendor_citrix·CVSS 7.5
CVE-2026-10816 [HIGH] Citrix Security Bulletin CTX696734
Citrix Security Bulletin CTX696734
CVE References: CVE-2026-10816, CVE-2026-10817, CVE-2026-13474, CVE-2026-3055, CVE-2026-42491, CVE-2026-4368, CVE-2026-53565, CVE-2026-53566, CVE-2026-8451, CVE-2026-8452, CVE-2026-8655
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Hackernews
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
blogs_hackernews·2026-08-27·CVSS 5.1
CVE-2019-1068 [MEDIUM] CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation.
The vulnerabilities are listed below -
CVE-2019-1068 - A remote code execution vulnerability in Microsoft SQL Server that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
CVE-2026-8452 - An impr
Hackernews
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
blogs_hackernews·2026-08-17·CVSS 9.8
CVE-2026-59310 [CRITICAL] ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
The expensive attacks are not always the clever ones.
This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely.
So, nothing magical. Just a lot of small openings turning into bigger problems. Here’s what stood out.
## ⚡ Threat of the Week
Suspected China APT Behind Exploitation of New V
Hackernews
Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
blogs_hackernews·2026-07-01·CVSS 7.1
CVE-2026-8451 [HIGH] Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
Citrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition.
The vulnerabilities are listed below -
CVE-2026-8451 (CVSS score: 8.8) - An insufficient input validation vulnerability leading to memory overread when NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
CVE-2026-8452 (CVSS score: 8.8) - A memory overflow vulnerab
2026-06-30
Published
2026-08-26
Added to CISA KEV
Exploited in the wild