Vulnerability
Published 2026-08-26
Verified 2026-08-29
Citrix NetScaler ADC/Gateway memory overflow (CVE-2026-8452)
CISA added CVE-2026-8452 to KEV on 26 August 2026 (federal due date 29 August 2026). NVD describes a memory-overflow issue in NetScaler ADC and NetScaler Gateway that can cause unpredictable behaviour and denial of service when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Apply the fixed builds in Citrix bulletin CTX696604. This desk does not invent build numbers the bulletin page would not yield over a plain fetch.
- Product
- Citrix NetScaler ADC and NetScaler Gateway
- Versions
- Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server configurations (see CTX696604)
- CVSS
- (CVSS 3.1, NVD); 8.8 (CVSS 4.0, vendor CNA)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Vendor fixed builds in CTX696604
Primary: Citrix CTX696604 · Vendor: NVD · CVE: CVE-2026-8452 · CISA KEV addition notice
