Active Exploitation of Citrix NetScaler ADC and NetScaler Gateway Vulnerability (CVE-2026-8452)
Security researchers have demonstrated that CVE-2026-8452 could lead to remote code execution (RCE)
Summary
Security researchers have demonstrated that CVE-2026-8452 could lead to remote code execution (RCE)
Affected platforms
The following platforms are known to be affected:
Threat details
Active Exploitation of CVE-2026-8452
Following the release of a public proof-of-concept exploit for CVE-2026-8452, security researchers have observed exploitation attempts against honeypots. The NHS England National CSOC assesses further exploitation as almost certain.
VPNs and other edge devices are internet-facing by design and are highly attractive targets to attackers, and there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers. Organisations are strongly encouraged to follow NCSC's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.
Introduction
Citrix published a security advisory for a vulnerability affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Successful exploitation of CVE-2026-8452 could lead to denial-of-service (DoS) or remote code execution (RCE) when the appliance is configured as a Gateway or an AAA virtual server.
- CVE-2026-8452 - 'Memory overflow' vulnerability - CVSSv4 score: 8.8
Note: While Citrix has described the impact as a denial-of-service condition, security researchers have published a proof of concept that demonstrates the vulnerability could lead to remote code execution (RCE).
Threat updates
| Date | Update |
|---|---|
| 17 Aug 2026 |
Escalated to High Severity following reports of active exploitation
The following sections have been updated:
|
Remediation advice
Affected organisations must review Citrix advisory CTX696604 and apply the relevant update as soon as possible.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Required: Update to a fixed version Fixed versions include:
Note: Citrix NetScaler 13.0 is end-of-life and no longer receives security updates. Organisations running end-of-life versions must upgrade to a supported version. https://support.citrix.com/external/article/CTX696604 |
Definitive source of threat updates
Last edited: 17 August 2026 11:46 am