CISA added CVE-2026-8452, a network-reachable memory buffer flaw in Citrix NetScaler ADC and NetScaler Gateway, to its Known Exploited Vulnerabilities catalog on 2026-08-26 with a three-day remediation deadline.
What Is It
CVE-2026-8452 is an improper restriction of operations within the bounds of a memory buffer (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway. Per NVD, the memory overflow leads to unpredictable or erroneous behavior and denial of service when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server.
NVD assigns a CVSS 3.1 base score of 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. A secondary CVSS 4.0 score from the CNA rates it 8.8 (HIGH). The record was published 2026-06-30 and last modified 2026-08-26, with a status of Analyzed.
Why It Matters
The vulnerability is network-exploitable at low attack complexity with no privileges and no user interaction; the classic profile for an internet-facing edge device. CISA's SSVC assessment for this CVE records exploitation as active and automatable as yes, and its addition to the KEV catalog confirms exploitation in the wild. Known ransomware campaign use is listed as Unknown.
What's Vulnerable
Affected builds, per the CNA data:
- NetScaler ADC 14.1: before 14.1-72.61
- NetScaler ADC 13.1: before 13.1-63.18
- NetScaler ADC 14.1 FIPS: before 14.1-72.61 (14.1-66.68 FIPS explicitly listed as vulnerable)
- NetScaler ADC 13.1 FIPS and NDcPP: before 13.1-37.272
- NetScaler Gateway 14.1: before 14.1-72.61
- NetScaler Gateway 13.1: before 13.1-63.18
Exposure requires the appliance to be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
Patch Status
CISA's required action: apply mitigations per vendor instructions in accordance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Due date: 2026-08-29: three days after the KEV listing. Vendor fix details are in Citrix advisory CTX696604.
Sources
- Citrix Vendor Advisory (CTX696604), https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8452
- NVD, CVE-2026-8452, https://nvd.nist.gov/vuln/detail/CVE-2026-8452
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk