🔴 CVE-2026-8452

CVE-2026-8452 is a memory overflow (CWE-119) vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers. It is unauthenticated, network-reachable, and has demonstrated pre-authentication remote code execution as root, with active in-the-wild exploitation and CISA KEV listing. This represents a critical, direct T1190 perimeter compromise risk.

← Back to Overview
HIGH_RISK
Risk Level
8.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-06-30

Added to CISA KEV: 2026-08-26 57 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-09-14)

Summary

CVE-2026-8452 is a memory overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances that can lead to system instability, denial of service (DoS), or, more critically, unauthenticated remote code execution (RCE). Initially identified as a DoS risk, research demonstrated that the flaw allows attackers to achieve root-level code execution when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, particularly when using SAML as a Service Provider or Identity Provider. It is a high-severity issue that poses a significant threat to organizational infrastructure due to its potential for total system compromise.

Exploitation

  • Active Exploitation: The vulnerability is being actively exploited in the wild [1].
  • Known Campaigns: It has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog [1].
  • PoC Availability: A public proof-of-concept (PoC) exploit demonstrating pre-authentication remote code execution is available [1][2].
  • Attack Prerequisites: Exploitation is network-based and does not require authentication; it is reachable when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), an AAA virtual server, or is using SAML as an SP/IdP [2][3].

Affected Products & Patches

  • Affected Products: Citrix NetScaler ADC and NetScaler Gateway appliances are affected when configured for Gateway functions (SSL VPN, ICA Proxy, etc.) or AAA virtual servers [3][4].
  • Patch Status: Security bulletins have been issued for the vulnerability; administrators should consult the official Citrix/NetScaler support portal to identify and apply the relevant security updates immediately.
  • Mitigations: Organizations that cannot patch immediately should verify their appliance configurations and ensure they are following the latest hardening and security guidance provided by the vendor.

Impact

  • Access & Capability: Successful exploitation allows an unauthenticated, remote attacker to execute arbitrary code as root, effectively gaining full control over the affected appliance.
  • Business Risk: For internet-facing deployments, this vulnerability provides a direct pathway for attackers to compromise the perimeter, steal sensitive credentials, intercept traffic, or pivot into the internal network, representing an extreme risk to the confidentiality, integrity, and availability of the entire organization.

Sources

  1. Citrix NetScaler RCE Flaw Exploited in Wild | YuSMP

    CVE-2026-8452 is a memory overflow in Citrix NetScaler ADC and Gateway, originally rated a denial-of-service risk when it shipped in June 2026. Security firm watchTowr published a proof-of-concept in August showing the flaw allows unauthenticated remote code execution as root. CISA added it to its K…

  2. GitHub - watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth...

    Citrix NetScaler PreAuth Heap overflow to RCE Detection Artifact Generator -. Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber). CVEs: [CVE-2026-8452] [*].Affected Versions. Tthe vulnerability is reachable when the Netscaler appliance is configured to use SAML as either a Service Provider…

  3. NVD-CVE-2026-8452 - NIST

    Description. Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of ... CVE-2026-8452 Detail Description Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial…

  4. CVE-2026-8452: Citrix NetScaler ADC DoS Vulnerability

    CVE-2026-8452 is a memory overflow denial of service vulnerability in Citrix NetScaler ADC and Gateway that causes system instability when ... CVE-2026-8452: Citrix NetScaler ADC DoS Vulnerability CVE-2026-8452 is a memory overflow denial of service vulnerability in Citrix NetScaler ADC and Gateway…