Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
Is CVE-2026-8452 exploited?
Listed in the CISA KEV catalog on 2026-08-26.
Federal remediation due 2026-08-29.
Past that date by 32 days.
Public exploit code: none found in monitored sources.
Which products and versions are affected?
Citrix Systems · NetScaler · Gateway <13.1-63.18
Citrix Systems · NetScaler · Gateway <14.1-72.61
Citrix Systems · NetScaler · ADC <13.1-NDcPP 13.1.37.272
Citrix Systems · NetScaler · ADC <13.1-FIPS 13.1.37.272