CVE-2026-8655
published 2026-06-30CVE-2026-8655: Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if…
PriorityP358critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.63%
48.2th percentile
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_application_delivery_controller | < 13.1-37.272 | 13.1-37.272 |
| citrix | netscaler_application_delivery_controller | — | — |
| citrix | netscaler_application_delivery_controller | >= 13.1 < 13.1-63.18 | 13.1-63.18 |
| citrix | netscaler_application_delivery_controller | >= 14.1 < 14.1-72.61 | 14.1-72.61 |
| citrix | netscaler_gateway | — | — |
| citrix | netscaler_gateway | >= 13.1 < 13.1-63.18 | 13.1-63.18 |
| citrix | netscaler_gateway | >= 14.1 < 14.1-72.61 | 14.1-72.61 |
| citrix | xenserver | — | — |
| netscaler | adc | >= 13.1 < 63.18 | 63.18 |
| netscaler | adc | >= 13.1 FIPS and NDcPP < 37.272 | 37.272 |
| netscaler | adc | >= 14.1 < 72.61 | 72.61 |
| netscaler | adc | >= 14.1 FIPS < 72.61 | 72.61 |
| netscaler | gateway | >= 13.1 < 63.18 | 63.18 |
| netscaler | gateway | >= 14.1 < 72.61 | 72.61 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Ora
ghsa_unreviewed·2026-06-30
CVE-2026-8655 [HIGH] CWE-119 Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Ora
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
VulDB
Citrix NetScaler ADC/NetScaler Gateway prior 37.272/63.18/72.61 denial of service (CTX696604 / EUVD-2026-40308)
vuldb·2026-06-30·CVSS 8.8
CVE-2026-8655 [HIGH] Citrix NetScaler ADC/NetScaler Gateway prior 37.272/63.18/72.61 denial of service (CTX696604 / EUVD-2026-40308)
A vulnerability labeled as problematic has been found in Citrix NetScaler ADC and NetScaler Gateway. The impacted element is an unknown function. The manipulation results in denial of service.
This vulnerability is reported as CVE-2026-8655. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
Citrix
Citrix Security Bulletin CTX696604
vendor_citrix·CVSS 8.8
CVE-2025-5349 [HIGH] Citrix Security Bulletin CTX696604
Citrix Security Bulletin CTX696604
CVE References: CVE-2025-5349, CVE-2025-5777, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397, CVE-2026-8451, CVE-2026-8452, CVE-2026-8655
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX696734
vendor_citrix·CVSS 7.5
CVE-2026-10816 [HIGH] Citrix Security Bulletin CTX696734
Citrix Security Bulletin CTX696734
CVE References: CVE-2026-10816, CVE-2026-10817, CVE-2026-13474, CVE-2026-3055, CVE-2026-42491, CVE-2026-4368, CVE-2026-53565, CVE-2026-53566, CVE-2026-8451, CVE-2026-8452, CVE-2026-8655
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
2026-06-30
Published