CVE-2026-8452
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Description
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
Description as published by the source, in English.
Key facts
- Published
- 2026-06-30
- Last modified
- 2026-08-27
- Assigned by
- 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Scored by
- nvd@nist.gov (NVD Primary)
- Probability of exploitation
-
0.5 %
higher than 39 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Not registered in the sources
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-08-26, with a remediation deadline of 2026-08-29 for US federal agencies.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Citrix | Netscaler Application Delivery Controller | < 13.1-37.272 | Affected |
| Citrix | Netscaler Application Delivery Controller | 14.1-66.68 | Affected |
| Citrix | Netscaler Application Delivery Controller | ≥ 13.1, < 13.1-63.18 | Affected |
| Citrix | Netscaler Application Delivery Controller | ≥ 14.1, < 14.1-72.61 | Affected |
| Citrix | Netscaler Gateway | ≥ 13.1, < 13.1-63.18 | Affected |
| Citrix | Netscaler Gateway | ≥ 14.1, < 14.1-72.61 | Affected |
Weakness type
-
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations tha…
References
- https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8452
Related at Berigo
Articles
-
Nine vulnerabilities entered the exploited catalogue in two days
Mentions this CVE
2026-09-01
CISA catalogued three more vulnerabilities on 27 August 2026, a day after six others went in. The three cover ownCloud, the Linux kernel and JFrog Ar…
-
Citrix reports multiple vulnerabilities in NetScaler ADC and Gateway
Mentions this CVE
2026-06-30
Citrix has published a bulletin covering multiple NetScaler ADC and Gateway vulnerabilities, scored 6.9 to 8.8 in CVSSv4 and requiring no authenticat…
-
Five of the six new KEV entries date from 2015 to 2022
Same product
2026-08-27
CISA has added six vulnerabilities to its Known Exploited Vulnerabilities catalogue. Five were published between 2015 and 2022, and three grant nothi…
-
Unit 42: Chinese speaking actor ran autonomous attacks with an AI agent
Same product
2026-07-31
On 30 July 2026 Unit 42 published a campaign in which a Chinese speaking actor let an AI agent find targets, fetch exploit code and attempt exploitat…
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.