• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-8452: pre-auth remote code execution in Citrix NetScaler ADC and NetScaler Gateway

An unauthenticated attacker can trigger a memory overflow in Citrix NetScaler ADC and NetScaler Gateway to crash the appliance or execute code; tracked as CVE-2026-8452. Affected releases include ADC 72.x (14.1 before 72.61), ADC 63.x (13.1 before 63.18), ADC 37.x (13.1 FIPS/NDcPP before 37.272) and Gateway branches listed for 63.x and 72.x. The vulnerability is remotely reachable over the network and does not require valid credentials or user interaction to exploit.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.01011
CWE
CWE-119
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: this is listed on CISA’s Known Exploited Vulnerabilities catalog with a short federal remediation deadline, and public exploit code exists, so prioritize applying vendor fixes or mitigations immediately.

What is CVE-2026-8452?

An unauthenticated attacker can trigger a memory overflow in Citrix NetScaler ADC and NetScaler Gateway to crash the appliance or execute code; tracked as CVE-2026-8452. Affected releases include ADC 72.x (14.1 before 72.61), ADC 63.x (13.1 before 63.18), ADC 37.x (13.1 FIPS/NDcPP before 37.272) and Gateway branches listed for 63.x and 72.x. The vulnerability is remotely reachable over the network and does not require valid credentials or user interaction to exploit.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Citrix NetScaler ADC and NetScaler Gateway are affected?

BRANCHAFFECTEDFIXED
ADC 72.x14.1 – before 72.6172.61
ADC 63.x13.1 – before 63.1863.18
ADC 72.x14.1 FIPS – before 72.6172.61
ADC 37.x13.1 FIPS and NDcPP – before 37.27237.272
Gateway 72.x14.1 – before 72.6172.61
Gateway 63.x13.1 – before 63.1863.18

Is CVE-2026-8452 being exploited?

CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog on 2026-08-26; U.S. federal agencies were required to address it by 2026-08-29. Public exploit code for the vulnerability is available.

How to fix CVE-2026-8452

  1. Apply Citrix fixes: upgrade ADC 72.x and Gateway 72.x to 72.61, ADC/Gateway 63.x to 63.18, and ADC 37.x to 37.272.
  2. If you cannot patch immediately, restrict network exposure of NetScaler appliances to trusted management networks and block untrusted internet access.
  3. Follow Citrix hardening guidance and monitor appliance logs for crashes or anomalous connections against Gateway and AAA virtual servers.
  4. Plan and implement the vendor-recommended mitigations and verify successful installation on each appliance.

Frequently asked questions

Is CVE-2026-8452 being actively exploited?

CISA added CVE-2026-8452 to the Known Exploited Vulnerabilities catalog on 2026-08-26 and required remediation by 2026-08-29, and public exploit code is available.

Which Citrix NetScaler ADC and Gateway versions are affected by CVE-2026-8452?

Affected versions include ADC 72.x (14.1 before 72.61), ADC 63.x (13.1 before 63.18), ADC 37.x (13.1 FIPS/NDcPP before 37.272) and the corresponding Gateway 63.x and 72.x branches listed by the vendor.

Is there a patch for CVE-2026-8452?

Yes; Citrix published fixes: 72.61 for 72.x branches, 63.18 for 63.x branches, and 37.272 for the 37.x branch—apply the matching fixed release for your appliance.

Does CVE-2026-8452 require authentication?

No; the vulnerability can be reached remotely without authentication against affected Citrix NetScaler ADC and Gateway deployments.

References