Cybersecurity Blog | RedLegg

Security Bulletin: Memory Overflow Vulnerability in Citrix NetScaler ADC and NetScaler Gateway

Written by RedLegg's Cyber Threat Intelligence Team | 8/27/26, 5:35 PM

About:

CVE-2026-8452 is a high-severity memory overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances configured as a Gateway or AAA virtual server.

The vulnerability affects appliances with Gateway functionality enabled. Administrators can determine potential exposure by checking the NetScaler configuration for add authentication vserver, indicating an AAA virtual server, or add vpn vserver, indicating a Gateway configuration.

Successful exploitation may compromise affected NetScaler environments. CVE-2026-8452 is confirmed to be actively exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.

RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.

VULNERABILITIES

Memory Overflow Vulnerability in Citrix NetScaler ADC and NetScaler Gateway

Identifier: CVE-2026-8452 
PoC or Exploitation:  Confirmed actively exploited in the wild. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog.  
CVSS Score: 8.8 (High, CVSS v4.0)

Update / Patch:

Cloud Software Group has released fixed versions addressing this vulnerability.
 
Affected versions include:
  • NetScaler ADC and NetScaler Gateway 14.1, before 14.1-72.61
  • NetScaler ADC and NetScaler Gateway 13.1, before 13.1-63.18
  • NetScaler ADC FIPS, before 14.1-72.61 FIPS
  • NetScaler ADC FIPS and NDcPP, before 13.1-37.272
 
Fixed versions include:
  • NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS: 14.1-72.61-FIPS and later releases
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP: 13.1.37.272 and later releases
 
Citrix Support Article CTX696604:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604


Description:

CVE-2026-8452 is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway.
 
This vulnerability applies when the appliance is configured as a Gateway.
 
Administrators can check whether an appliance meets these preconditions by inspecting the NetScaler configuration for the strings add authentication vserver, indicating an AAA virtual server, or add vpn vserver, indicating a Gateway configuration.

 

Mitigation Recommendation:

Apply the applicable fixed version for your NetScaler ADC or Gateway deployment immediately.
 
Confirm your appliance configuration against the precondition check above to determine your exposure. Appliances not configured as a Gateway or AAA virtual server are not affected.
 
Check affected appliances for webshells and other unauthorized files.
 
Review NetScaler system logs for unexpected Packet Engine process restarts or crashes on Gateway or AAA-enabled appliances, as well as any anomalous inbound traffic preceding such events.
 
Restrict access to the management interface to trusted networks or a VPN.