CVE-2026-8452: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-08-26. EPSS: 1% chance of exploitation in the next 30 days.
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
Affected products
- Citrix NetScaler Application Delivery Controller: before 13.1-37.272 (fixed in 13.1-37.272); from 13.1, before 13.1-63.18 (fixed in 13.1-63.18); from 14.1, before 14.1-72.61 (fixed in 14.1-72.61); version 14.1-66.68 only
- Citrix NetScaler Gateway: from 13.1, before 13.1-63.18 (fixed in 13.1-63.18); from 14.1, before 14.1-72.61 (fixed in 14.1-72.61)
Published 2026-06-30. Last modified 2026-08-27.