Threat Insight
Critical Citrix NetScaler Memory-Overflow Vulnerability
A high-severity memory-overflow vulnerability in Citrix NetScaler appliances has recently been urged to be immediately addressed by The Cybersecurity and Infrastructure Security Agency (CISA).
Citrix initially described it as capable of causing unpredictable behavior or denial-of-service conditions, while research by WatchTowr[1] demonstrated that it can potentially be exploited for unauthenticated remote code execution. For successful exploitation it must be a Citrix NetScaler running a vulnerable version and must be configured as either a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or a AAA virtual server.
CVE
CVE-2026-8452
Affected Products
NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-72.61
NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.18
NetScaler ADC FIPS BEFORE 14.1-72.61 FIPS
NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.272
Exploitation
CVE-2026-8452 has recently been added to the CISA database of known exploited vulnerabilities[2].
Recommended Actions
Truesec recommends upgrading to the patched NetScaler firmware versions.
To determine whether the appliance meets the preconditions, inspect the NetScaler configuration and look for the following strings[3]:
- An Auth Server (AAA Vserver): add authentication vserver .*
- A Gateway (VPN Vserver, ICA Proxy, CVPN, RDP Proxy) : add vpn vserver .*
References
[1] https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452
[2] https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog
[3] https://support.citrix.com/external/article/CTX696604/netscaler-adc-and-netscaler-gateway-secu.html
Stay ahead with cyber insights
Newsletter
Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.
Your current browser privacy settings may be preventing this form from loading properly. To continue, please allow cookies/tracking for this site or temporarily disable strict privacy protection, then refresh the page.
If you’re still experiencing issues, please contact us at hello@truesec.com