CRITICAL

CVE-2026-8452

Citrix Netscaler Application Delivery Controller 2026-06-30 CVSS v3.1
CVSS
9.8
KEV

Description

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

Summary dbcve.org

A memory overflow vulnerability exists in Citrix NetScaler ADC and NetScaler Gateway when configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. The memory corruption can lead to unpredictable or erroneous behavior and potentially complete Denial of Service of the appliance.

Mitigation

Apply the relevant Citrix security patch/firmware update for this vulnerability. If immediate patching is not possible, consider restricting exposure of vulnerable virtual server configurations or implementing additional network-level controls to limit attack surface.

Weakness (CWE)

CWE-119 Memory Buffer Bounds Error

EPSS Score

1.61%
Probability of exploitation in next 30 days
74.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE