Critical Citrix NetScaler Memory-Overflow Vulnerability
Brief
Citrix initially described it as capable of causing unpredictable behavior or denial-of-service conditions, while research by WatchTowr[1] demonstrated that it can potentially be exploited for unauthenticated remote code execution.
For successful exploitation it must be a Citrix NetScaler running a vulnerable version and must be configured as either a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or a AAA virtual server.
CVE
CVE-2026-8452
Affected Products
NetScaler ADC and NetScaler Gateway 14. 1 BEFORE 14. 1-72. 61 NetScaler ADC and NetScaler Gateway 13. 1 BEFORE 13. 1-63. 18 NetScaler ADC FIPS BEFORE 14. 1-72. 61 FIPS NetScaler ADC FIPS and NDcPP BEFORE 13. 1-37. 272
Exploitation
CVE-2026-8452 has recently been added to the CISA database of known exploited vulnerabilities[2].
