Critical 9.8 Actively Exploited

NetScaler ADC crash exploited in the wild (CVE-2026-8452) [PoC]

CVE-2026-8452

By Yazoul AI · automated

CVE-2026-8452: NetScaler ADC/Gateway 14.1 memory overflow causes DoS, actively exploited. CVSS 9.8. Update to 14.1-29.61 or disable affected features.

Affected: Citrix Netscaler Application Delivery Controller Citrix Netscaler Gateway

Actively exploited in the wild - CVE-2026-8452 is a critical memory overflow in NetScaler ADC and NetScaler Gateway 14.1-29.54 and earlier that lets unauthenticated remote attackers crash the appliance when configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Patched in NetScaler 14.1-29.61 - update immediately.

Overview

CVE-2026-8452 is a memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway appliances. Attackers can trigger the flaw over the network without any credentials or user interaction, making it trivially exploitable. The high CVSS score of 9.8 reflects both the ease of exploitation and the severity of the impact: complete denial of service on affected appliances.

The vulnerability only manifests when the appliance runs specific configurations. Devices acting as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server are exposed. Other NetScaler ADC configurations may not be reachable by this exploit.

Impact

A successful exploit causes unpredictable or erroneous behavior in the appliance, culminating in a full denial of service. This means VPN sessions drop, remote access terminates, and all applications proxied through the appliance become unreachable. For organizations relying on NetScaler for remote workforce access, this can halt operations entirely.

CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score sits at 1.0%, indicating a moderate probability of broader exploitation in the next 30 days, though that figure climbs as public proof-of-concept code circulates.

Remediation

NetScaler has released a fix. Upgrade to the following versions:

  • NetScaler ADC and Gateway 14.1-29.61 or later

If immediate patching is not possible, apply these mitigations:

  • Remove affected virtual server types (SSL VPN, ICA Proxy, CVPN, RDP Proxy, AAA) until the patch is applied
  • Restrict network access to management interfaces using firewall rules
  • Monitor logs for anomalous traffic patterns targeting these services

The vendor advisory is available on the NetScaler security bulletin page. Also check breach reports for indicators of compromise and security news for follow-up coverage.

Security Insight

This is the second critical NetScaler memory overflow in under a year, signaling a pattern of memory-safety issues in the appliance’s networking stack. Attackers increasingly target edge devices because one bug yields access to an entire remote workforce. The active exploitation of CVE-2026-8452 within days of disclosure shows that threat actors automate attacks against Citrix/NetScaler infrastructure faster than many organizations can patch, reinforcing that edge devices should be treated as high-risk endpoints requiring rapid mitigation plans.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Public PoC References

Unverified third-party code

These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).

Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.

Repository Stars
watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

CVE-2026-8452 PreAuth RCE

★ 58

Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.

Related Advisories

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.