AI description
CVE-2026-8452 is identified as a memory overflow vulnerability impacting Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway appliances. This flaw can result in unpredictable or erroneous behavior and may lead to a Denial of Service (DoS) condition. The vulnerability is present when the appliance is configured as a Gateway, supporting functions such as SSL VPN, ICA Proxy, Clientless VPN (CVPN), or RDP Proxy, or when it operates as an AAA virtual server. The vulnerability is reachable over the network and does not require authentication or user interaction for exploitation. In some configurations, particularly involving the SSL VPN portal component and a malformed TLS handshake, it has been described as a pre-authentication Remote Code Execution (RCE) vulnerability, stemming from a heap overflow in the SAML message normalization process. This can allow an attacker to trigger memory corruption and potentially install a webshell with root privileges.
- Description
- Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
- Source
- 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
- NVD status
- Analyzed
- Products
- netscaler_application_delivery_controller, netscaler_gateway
CVSS 4.0
- Type
- Secondary
- Base score
- 8.8
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-119
- Hype score
- Not currently trending
Citrix NetScalerの事前認証RCE脆弱性(CVE-2026-8452)の悪用コードが公開される Citrix NetScaler Pre-Auth RCE CVE-2026-8452 Gets Public Exploit Code #DailyCyberSecurity (Aug 17) https://t.co/Fh5Oo2jKlv
@foxbook
18 Aug 2026
277 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-8452: Citrix NetScaler Pre-Auth RCE https://t.co/hV6GOPgXZu
@mjadaaan
17 Aug 2026
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-8452: Citrix NetScaler Pre-Auth RCE PoC Out - https://t.co/ZawxATCkbU
@moton
17 Aug 2026
43 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
PoC exploit code for CVE-2026-8452, a Citrix NetScaler pre-auth RCE, is now public. The SAML heap overflow grants root. Patch now. #Citrix #NetScaler #CVE #PreAuthRCE #SAML #CyberSecurity #InfoSec #PatchNow https://t.co/cs59uHMA7d
@Daily_CyberSec
17 Aug 2026
143 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
NetScaler ADCおよびNetScaler Gatewayにおけるリモートコード実行につながる脆弱性(CVE-2026-8452)に関する注意喚起 #JPCERTCC (Aug 15) https://t.co/gxHG9vCS5o
@foxbook
16 Aug 2026
324 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?) by watchTowr Team 🤯🔥 👨💻 Sina Kheirkhah (x/sinsinology) 🔗 https://t.co/PivIBHo4ze 🔗 https://t.co/pYnAk896OO 🔗 Join team 👉https://t.co/cADA5DUdp5 https://t.co/E5AEsL2o97
@luckyhacker43
16 Aug 2026
1626 Impressions
2 Retweets
23 Likes
11 Bookmarks
0 Replies
0 Quotes
Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?) by watchTowr Team 🤯🔥 👨💻 Sina Kheirkhah (x/sinsinology) 🔗 https://t.co/UnfzE3GcsX 🔗 https://t.co/YAtufLi75O https://t.co/78VUkZfi9q
@N45HTOfficial
16 Aug 2026
1305 Impressions
2 Retweets
21 Likes
11 Bookmarks
0 Replies
1 Quote
🚨إذا كنت تستخدم #Citrix-#Netscaler قم بالتحديث على الفور لوجود ثغرة CVE-2026-8452 يمكن استغلالها عن بعد، أداة الاستغلال منتشره وتفاصيل الثغرة كذلك: - https://t.co/Nv8WJQec0a - https:/
@MAlajab
15 Aug 2026
654 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
CyberSec Daily ✓ · 🌐 Vulnerability · August 14, 2026 🎯 Researchers publish analysis of possible NetScaler pre-authentication RCE WatchTowr researchers analyzed a NetScaler heap-overflow condition they believe corresponds to CVE-2026-8452. Their research demonstrates
@XQOPTRX
14 Aug 2026
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-8452: Citrix NetScaler Pre-Auth RCE Disclosed by watchTowr — Detection… "watchTowr Labs has published technical research detailing CVE-2026-8452, a pre-authentication…" 🔗 https://t.co/xWABcci1g6 #CyberSecurity #ThreatIntel #critical #zero
@SecurityAr58409
14 Aug 2026
65 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Security researchers at watchTowr Labs have published a detailed technical walkthrough demonstrating how CVE-2026-8452, a heap overflow vulnerability in Citrix NetScaler ADC and... https://t.co/2dvjpvKJaZ #Cybersecurity #InfoSec #CVE #HighSeverity #RemoteCodeExecution https://t.c
@CveTodo
14 Aug 2026
95 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Vulnerabilidades en productos Citrix ❗ CVE-2026-8655 ❗ CVE-2026-8452 ❗ CVE-2026-8451 ➡️ Más info: https://t.co/2dLfwsJi4C https://t.co/UwrkcXqHEb
@CERTpy
9 Jul 2026
231 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474 https://t.co/UGmoOer9KD #patchmanagement
@eyalestrin
4 Jul 2026
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Citrix has recently released new updates to fix NetScaler ADC and NetScaler Gateway, where attackers would be able to conduct file reads and/or trigger a Denial-of-Service condition. These updates resolves the following CVEs: -> CVE-2026-8451 -> CVE-2026-8452 -> CVE-20
@Leila97726926
4 Jul 2026
63 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-8452: Critical Citrix NetScaler Memory Overflow — Defense and Remediat… "Critical CVE-2026-8452 hits Citrix NetScaler. Immediate patching required for Gateway/AAA…" 🔗 https://t.co/wgUckXbCFb #CyberSecurity #ThreatIntel #cve20268452 #criti
@SecurityAr58409
3 Jul 2026
62 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 6 high-severity Citrix NetScaler flaws - CVE-2026-8451 - CVE-2026-8452 - CVE-2026-8655 - CVE-2026-10816 - CVE-2026-10817 - CVE-2026-13474 All six stem from improper memory handling/input validation, enabling DoS and memory overflow. Fixes: - 14.1 → upgrade to 14.1-72.61
@techepages
1 Jul 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨🚨🚨 NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474 https://t.co/5V1endcgNp
@autumn_good_35
1 Jul 2026
620 Impressions
0 Retweets
3 Likes
1 Bookmark
1 Reply
0 Quotes
🚨🚨🚨@cloudsoftware has just issued a security bulletin for @NetScaler 🚨🚨🚨 Severity: *** HIGH *** CVE: CVE-2026-8451 / CVE-2026-8452 / CVE-2026-8655 / CVE-2026-10816 / CVE-2026-10817 / CVE-2026-13474 For more information: https://t.co/GsLEmIbEMS
@jantytgat
30 Jun 2026
139 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*",
"matchCriteriaId": "D8189708-5190-45E3-BF9A-7A429E87DFE7",
"versionEndExcluding": "13.1-37.272",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*",
"matchCriteriaId": "D93A5760-5C50-4786-B981-24A7B35C3055",
"versionEndExcluding": "13.1-37.272",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*",
"matchCriteriaId": "BC139A27-D7CE-4D92-9A1F-09713C4C9546",
"versionEndExcluding": "13.1-63.18",
"versionStartIncluding": "13.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*",
"matchCriteriaId": "0108075C-1047-449C-A707-F2532770C2AD",
"versionEndExcluding": "14.1-72.61",
"versionStartIncluding": "14.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1-66.68:*:*:*:fips:*:*:*",
"matchCriteriaId": "A2BC089B-97D0-4FDB-A336-74409DCDC5E3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*",
"matchCriteriaId": "962D2276-7285-41E2-A867-D464AE11677F",
"versionEndExcluding": "13.1-63.18",
"versionStartIncluding": "13.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1591FBCE-57DD-416F-A858-E898B0946AB6",
"versionEndExcluding": "14.1-72.61",
"versionStartIncluding": "14.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]