Citrix NetScaler ADC and Gateway Memory Buffer Overflow
CVE-2026-8452 is a CVSS 9.8 critical memory buffer overflow in Citrix NetScaler ADC and NetScaler Gateway affecting appliances configured as Gateway or AAA virtual server, confirmed exploited in the wild and added to CISA KEV on August 26, 2026.
- Vendor
- Citrix
- Product
- NetScaler ADC and NetScaler Gateway
- CVSS
- 9.8
- EPSS (exploit probability)
- 1.6%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
CVE-2026-8452 is a memory buffer overflow in Citrix NetScaler ADC and NetScaler Gateway. The flaw is scoped to appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. Outside those roles, the vulnerability is not directly reachable via the same attack surface.
NVD rates it CVSS 9.8 critical. The described impact is unpredictable or erroneous behavior and denial of service. CISA added it to the Known Exploited Vulnerabilities catalog on August 26, 2026, confirming active exploitation in the wild.
Federal patch deadline: August 29, 2026, per BOD 26-04. CISA has also attached forensics triage requirements to this entry.
What to do: Apply mitigations per Citrix advisory CTX696604. For cloud-deployed NetScaler, follow BOD 26-04 cloud guidance, or discontinue use if mitigations are unavailable.
Full coverage: Patch by Friday: Citrix NetScaler CVE-2026-8452 in KEV.
