7 min read
By: RedLegg's Cyber Threat Intelligence Team
About:
CVE-2026-8452 is a high-severity memory overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances configured as a Gateway or AAA virtual server.
The vulnerability affects appliances with Gateway functionality enabled. Administrators can determine potential exposure by checking the NetScaler configuration for add authentication vserver, indicating an AAA virtual server, or add vpn vserver, indicating a Gateway configuration.
Successful exploitation may compromise affected NetScaler environments. CVE-2026-8452 is confirmed to be actively exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
VULNERABILITIES
Memory Overflow Vulnerability in Citrix NetScaler ADC and NetScaler Gateway
Identifier: CVE-2026-8452
PoC or Exploitation: Confirmed actively exploited in the wild. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog.
CVSS Score: 8.8 (High, CVSS v4.0)
Update / Patch:
- NetScaler ADC and NetScaler Gateway 14.1, before 14.1-72.61
- NetScaler ADC and NetScaler Gateway 13.1, before 13.1-63.18
- NetScaler ADC FIPS, before 14.1-72.61 FIPS
- NetScaler ADC FIPS and NDcPP, before 13.1-37.272
- NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
- NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
- NetScaler ADC 14.1-FIPS: 14.1-72.61-FIPS and later releases
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP: 13.1.37.272 and later releases
Description:
Mitigation Recommendation: