CVE-2026-8452
Citrix ADC VPX vulnerability analysis and mitigation

Overview

CVE-2026-8452 is a memory overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway that can lead to unpredictable or erroneous behavior and Denial of Service (DoS). The vulnerability is only exploitable when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-72.61, 13.1 before 13.1-63.18, and NetScaler ADC 13.1 FIPS/NDcPP before 13.1-37.272. It was published on June 30, 2026, with patches made available the same day. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 8.8 (High) (GitHub Advisory, Citrix Advisory).

Technical details

The root cause is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), where the product reads from or writes to memory locations outside the intended buffer boundary. An unauthenticated remote attacker can trigger this memory overflow by sending specially crafted network requests to a NetScaler appliance configured as a Gateway or AAA virtual server, requiring no privileges or user interaction. The flaw is automatable and exploitable over the network with low attack complexity, making it accessible to a wide range of threat actors. The vulnerability is part of a broader set of six NetScaler flaws patched simultaneously, including CVE-2026-8451, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474 (GitHub Advisory, Citrix Advisory).

Impact

Successful exploitation causes the NetScaler appliance to crash or behave unpredictably, resulting in a Denial of Service that disrupts SSL VPN, ICA Proxy, CVPN, RDP Proxy, and AAA authentication services for all connected users. The CVSS v4.0 scoring also indicates a high confidentiality impact on the vulnerable system, suggesting potential for memory content exposure alongside the availability impact. Organizations relying on NetScaler Gateway as a remote access or authentication gateway face significant operational disruption, and any memory disclosure could expose sensitive session or credential data in transit (GitHub Advisory, Citrix Advisory).

Indicators of compromise

  • Network: Unusual or malformed HTTP/HTTPS requests targeting NetScaler Gateway or AAA virtual server endpoints from unexpected source IPs; sudden spikes in connection attempts or request volume to Gateway interfaces.
  • Logs: NetScaler system logs showing unexpected crashes, core dumps, or process restarts of the nsppe or nshttpd processes; error messages indicating memory access violations or segmentation faults in /var/nslog/ or /var/log/.
  • Availability: Repeated or unexpected appliance reboots or service interruptions on Gateway or AAA virtual server interfaces without administrative action.
  • System: Unexpected core dump files generated in /var/core/ or similar directories on the NetScaler appliance following anomalous traffic patterns.

Mitigation and workarounds

Citrix has released patched versions addressing CVE-2026-8452: NetScaler ADC and Gateway 14.1-72.61 and later, NetScaler ADC and Gateway 13.1-63.18 and later, and NetScaler ADC 13.1 FIPS/NDcPP 13.1-37.272 and later. Organizations should prioritize patching appliances configured as Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers, as these are the directly vulnerable configurations. As an interim measure, consider restricting network access to the management and Gateway interfaces to trusted IP ranges while patches are being deployed (Citrix Advisory).

Community reactions

The vulnerability received broad coverage from security media outlets including The Hacker News, SecurityWeek, GBHackers, and Heise, with SecurityWeek noting the patch batch also addressed a novel "HTTP/2 bomb" attack vector (The Hacker News, SecurityWeek). The Stack Technology reported that Citrix credited JPMorgan for responsible disclosure of bugs in this patch batch. Government cybersecurity agencies including Canada's CCCS and Singapore's CSA issued advisories urging prompt patching. SOCRadar published a technical blog drawing comparisons to the earlier CitrixBleed vulnerability (CVE-2023-4966), highlighting the recurring risk profile of NetScaler Gateway products (SOCRadar).

Additional resources


SourceThis report was generated using AI

Related Citrix ADC VPX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8655HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-8452HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-8451HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-13474HIGH8.7
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-10817MEDIUM6.9
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management