Skip to main content

Active Exploitation of Citrix NetScaler ADC and NetScaler Gateway Vulnerability (CVE-2026-8452)

Security researchers have demonstrated that CVE-2026-8452 could lead to remote code execution (RCE)

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security researchers have demonstrated that CVE-2026-8452 could lead to remote code execution (RCE)


Threat details

Active Exploitation of CVE-2026-8452

Following the release of a public proof-of-concept exploit for CVE-2026-8452, security researchers have observed exploitation attempts against honeypots. The NHS England National CSOC assesses further exploitation as almost certain.

VPNs and other edge devices are internet-facing by design and are highly attractive targets to attackers, and there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers. Organisations are strongly encouraged to follow NCSC's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.


Introduction

Citrix published a security advisory for a vulnerability affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Successful exploitation of CVE-2026-8452 could lead to denial-of-service (DoS) or remote code execution (RCE) when the appliance is configured as a Gateway or an AAA virtual server. 

  • CVE-2026-8452 - 'Memory overflow' vulnerability -  CVSSv4 score: 8.8

Note: While Citrix has described the impact as a denial-of-service condition, security researchers have published a proof of concept that demonstrates the vulnerability could lead to remote code execution (RCE).


Threat updates

Date Update
17 Aug 2026 Escalated to High Severity following reports of active exploitation

The following sections have been updated:

  • Severity
  • Title
  • Exploitation details
  • Remediation advice
  • Remediation steps

Remediation advice

Affected organisations must review Citrix advisory CTX696604 and apply the relevant update as soon as possible.


Remediation steps

Type Step
Patch

Required: Update to a fixed version

Fixed versions include:

  • NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP

Note: Citrix NetScaler 13.0 is end-of-life and no longer receives security updates. Organisations running end-of-life versions must upgrade to a supported version.


https://support.citrix.com/external/article/CTX696604


Last edited: 17 August 2026 11:46 am