Citrix NetScaler ADC/Gateway memory overflow flaw (CVE-2026-8452)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-8452 is an actively exploited memory overflow flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, including systems configured with Gateway VPN or AAA virtual servers. Successful exploitation can reach remote code execution as root on unpatched instances. CISA added the flaw to the KEV Catalog and moved to force rapid remediation across vulnerable federal systems.
Related Happenings
NetScaler ADC/Gateway arbitrary file read security flaw (CVE-2026-10816)
Vulnerability
H score30
First: 01.07.2026 06:54
Last: 01.07.2026 06:54
Sources 1
About this happening:
Citrix's NetScaler ADC and NetScaler Gateway now have CVE-2026-10816, a 7.7 flaw that can expose files through unauthenticated arbitrary file read when managem...
NetScaler ADC/Gateway arbitrary file read security flaw (CVE-2026-10816)
VulnerabilityAbout this happening: Citrix's NetScaler ADC and NetScaler Gateway now have CVE-2026-10816, a 7.7 flaw that can expose files through unauthenticated arbitrary file read when managem...
CISA KEV order for CVE-2026-3055 on Citrix appliances
Public Sector Action
H score34
First: 31.03.2026 10:05
Last: 31.03.2026 10:05
Sources 1
About this happening:
CISA added CVE-2026-3055 to the KEV Catalog and ordered FCEB agencies to secure Citrix NetScaler appliances by Thursday, April 2, turning an actively exploit...
CISA KEV order for CVE-2026-3055 on Citrix appliances
Public Sector ActionAbout this happening: CISA added CVE-2026-3055 to the KEV Catalog and ordered FCEB agencies to secure Citrix NetScaler appliances by Thursday, April 2, turning an actively exploit...
Cloud Software Group NetScaler urgent remediation advisory
Advisory/Mitigation
H score44
First: 25.03.2026 17:52
Last: 25.03.2026 17:52
Sources 1
About this happening:
Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...
Cloud Software Group NetScaler urgent remediation advisory
Advisory/MitigationAbout this happening: Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...
Latest development: 31.07.2026 20:35
Unit 42 confirmed three successful compromises of Citrix NetScaler systems via CVE-2026-3055, with the threat actor extracting memory and searching for authentication cookies to hijack sessions, while also conducting manual attacks against more than 460 systems using vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products.
NetScaler ADC and NetScaler Gateway out-of-bounds read security flaw (CVE-2026-3055)
Vulnerability
H score38
First: 24.03.2026 17:15
Last: 24.03.2026 17:15
Sources 1
About this happening:
A critical out-of-bounds read in NetScaler ADC and NetScaler Gateway can let an unauthenticated remote attacker leak sensitive memory contents from affected ap...
NetScaler ADC and NetScaler Gateway out-of-bounds read security flaw (CVE-2026-3055)
VulnerabilityAbout this happening: A critical out-of-bounds read in NetScaler ADC and NetScaler Gateway can let an unauthenticated remote attacker leak sensitive memory contents from affected ap...
Citrix NetScaler reconnaissance scanning and version-enumeration campaign
Campaign
H score29
First: 03.02.2026 22:25
Last: 03.02.2026 22:25
Sources 1
About this happening:
A Citrix NetScaler reconnaissance campaign used residential proxies and 63,189 distinct IPs between January 28 and February 2 to map exposed login panels and EPA a...
Citrix NetScaler reconnaissance scanning and version-enumeration campaign
CampaignAbout this happening: A Citrix NetScaler reconnaissance campaign used residential proxies and 63,189 distinct IPs between January 28 and February 2 to map exposed login panels and EPA a...
Timeline
-
27.08.2026 12:16 2 articles · 10h ago
CISA adds CVE-2026-8452 to the KEV Catalog and orders federal patching
Legal Policy Action UpdateCISA added CVE-2026-8452 to its Known Exploited Vulnerabilities (KEV) Catalog and ordered Federal Civilian Executive Branch (FCEB) agencies to secure vulnerable Citrix NetScaler appliances by August 29 under Binding Operational Directive (BOD) 26-04. The memory-overflow flaw affects NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA virtual servers, and researchers said successful exploitation in August can lead to remote code execution as root on unpatched instances after Citrix said in June that the issue appeared limited to denial-of-service attacks.
Show sources
- CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday — www.bleepingcomputer.com — 27.08.2026 12:16
- CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday — www.bleepingcomputer.com — 27.08.2026 12:16