CVE-2026-8452

Published Jun 30, 2026

Last updated 2 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-8452 is identified as a memory overflow vulnerability impacting Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway appliances. This flaw can result in unpredictable or erroneous behavior and may lead to a Denial of Service (DoS) condition. The vulnerability is present when the appliance is configured as a Gateway, supporting functions such as SSL VPN, ICA Proxy, Clientless VPN (CVPN), or RDP Proxy, or when it operates as an AAA virtual server. The vulnerability is reachable over the network and does not require authentication or user interaction for exploitation. In some configurations, particularly involving the SSL VPN portal component and a malformed TLS handshake, it has been described as a pre-authentication Remote Code Execution (RCE) vulnerability, stemming from a heap overflow in the SAML message normalization process. This can allow an attacker to trigger memory corruption and potentially install a webshell with root privileges.

Description
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
Source
50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
NVD status
Analyzed
Products
netscaler_application_delivery_controller, netscaler_gateway

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.8
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-119

Social media

Hype score
Not currently trending
  1. Citrix NetScalerの事前認証RCE脆弱性(CVE-2026-8452)の悪用コードが公開される Citrix NetScaler Pre-Auth RCE CVE-2026-8452 Gets Public Exploit Code #DailyCyberSecurity (Aug 17) https://t.co/Fh5Oo2jKlv

    @foxbook

    18 Aug 2026

    277 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2026-8452: Citrix NetScaler Pre-Auth RCE https://t.co/hV6GOPgXZu

    @mjadaaan

    17 Aug 2026

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2026-8452: Citrix NetScaler Pre-Auth RCE PoC Out - https://t.co/ZawxATCkbU

    @moton

    17 Aug 2026

    43 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  4. PoC exploit code for CVE-2026-8452, a Citrix NetScaler pre-auth RCE, is now public. The SAML heap overflow grants root. Patch now. #Citrix #NetScaler #CVE #PreAuthRCE #SAML #CyberSecurity #InfoSec #PatchNow https://t.co/cs59uHMA7d

    @Daily_CyberSec

    17 Aug 2026

    143 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. NetScaler ADCおよびNetScaler Gatewayにおけるリモートコード実行につながる脆弱性(CVE-2026-8452)に関する注意喚起 #JPCERTCC (Aug 15) https://t.co/gxHG9vCS5o

    @foxbook

    16 Aug 2026

    324 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  6. Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?) by watchTowr Team 🤯🔥 👨‍💻 Sina Kheirkhah (x/sinsinology) 🔗 https://t.co/PivIBHo4ze 🔗 https://t.co/pYnAk896OO 🔗 Join team 👉https://t.co/cADA5DUdp5 https://t.co/E5AEsL2o97

    @luckyhacker43

    16 Aug 2026

    1626 Impressions

    2 Retweets

    23 Likes

    11 Bookmarks

    0 Replies

    0 Quotes

  7. Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?) by watchTowr Team 🤯🔥 👨‍💻 Sina Kheirkhah (x/sinsinology) 🔗 https://t.co/UnfzE3GcsX 🔗 https://t.co/YAtufLi75O https://t.co/78VUkZfi9q

    @N45HTOfficial

    16 Aug 2026

    1305 Impressions

    2 Retweets

    21 Likes

    11 Bookmarks

    0 Replies

    1 Quote

  8. 🚨إذا كنت تستخدم #Citrix-#Netscaler قم بالتحديث على الفور لوجود ثغرة CVE-2026-8452 يمكن استغلالها عن بعد، أداة الاستغلال منتشره وتفاصيل الثغرة كذلك: - https://t.co/Nv8WJQec0a - https:/

    @MAlajab

    15 Aug 2026

    654 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  9. CyberSec Daily ✓ · 🌐 Vulnerability · August 14, 2026 🎯 Researchers publish analysis of possible NetScaler pre-authentication RCE WatchTowr researchers analyzed a NetScaler heap-overflow condition they believe corresponds to CVE-2026-8452. Their research demonstrates

    @XQOPTRX

    14 Aug 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🔒 #CyberSecurity CVE-2026-8452: Citrix NetScaler Pre-Auth RCE Disclosed by watchTowr — Detection… "watchTowr Labs has published technical research detailing CVE-2026-8452, a pre-authentication…" 🔗 https://t.co/xWABcci1g6 #CyberSecurity #ThreatIntel #critical #zero

    @SecurityAr58409

    14 Aug 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Security researchers at watchTowr Labs have published a detailed technical walkthrough demonstrating how CVE-2026-8452, a heap overflow vulnerability in Citrix NetScaler ADC and... https://t.co/2dvjpvKJaZ #Cybersecurity #InfoSec #CVE #HighSeverity #RemoteCodeExecution https://t.c

    @CveTodo

    14 Aug 2026

    95 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. ⚠️ Vulnerabilidades en productos Citrix ❗ CVE-2026-8655 ❗ CVE-2026-8452 ❗ CVE-2026-8451 ➡️ Más info: https://t.co/2dLfwsJi4C https://t.co/UwrkcXqHEb

    @CERTpy

    9 Jul 2026

    231 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474 https://t.co/UGmoOer9KD #patchmanagement

    @eyalestrin

    4 Jul 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Citrix has recently released new updates to fix NetScaler ADC and NetScaler Gateway, where attackers would be able to conduct file reads and/or trigger a Denial-of-Service condition. These updates resolves the following CVEs: -> CVE-2026-8451 -> CVE-2026-8452 -> CVE-20

    @Leila97726926

    4 Jul 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🔒 #CyberSecurity CVE-2026-8452: Critical Citrix NetScaler Memory Overflow — Defense and Remediat… "Critical CVE-2026-8452 hits Citrix NetScaler. Immediate patching required for Gateway/AAA…" 🔗 https://t.co/wgUckXbCFb #CyberSecurity #ThreatIntel #cve20268452 #criti

    @SecurityAr58409

    3 Jul 2026

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 6 high-severity Citrix NetScaler flaws - CVE-2026-8451 - CVE-2026-8452 - CVE-2026-8655 - CVE-2026-10816 - CVE-2026-10817 - CVE-2026-13474 All six stem from improper memory handling/input validation, enabling DoS and memory overflow. Fixes: - 14.1 → upgrade to 14.1-72.61

    @techepages

    1 Jul 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🚨🚨🚨 NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474 https://t.co/5V1endcgNp

    @autumn_good_35

    1 Jul 2026

    620 Impressions

    0 Retweets

    3 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  18. 🚨🚨🚨@cloudsoftware has just issued a security bulletin for @NetScaler 🚨🚨🚨 Severity: *** HIGH *** CVE: CVE-2026-8451 / CVE-2026-8452 / CVE-2026-8655 / CVE-2026-10816 / CVE-2026-10817 / CVE-2026-13474 For more information: https://t.co/GsLEmIbEMS

    @jantytgat

    30 Jun 2026

    139 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations