NetScaler ADC crash exploited in the wild (CVE-2026-8452) [PoC]
CVE-2026-8452
CVE-2026-8452: NetScaler ADC/Gateway 14.1 memory overflow causes DoS, actively exploited. CVSS 9.8. Update to 14.1-29.61 or disable affected features.
Actively exploited in the wild - CVE-2026-8452 is a critical memory overflow in NetScaler ADC and NetScaler Gateway 14.1-29.54 and earlier that lets unauthenticated remote attackers crash the appliance when configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Patched in NetScaler 14.1-29.61 - update immediately.
Overview
CVE-2026-8452 is a memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway appliances. Attackers can trigger the flaw over the network without any credentials or user interaction, making it trivially exploitable. The high CVSS score of 9.8 reflects both the ease of exploitation and the severity of the impact: complete denial of service on affected appliances.
The vulnerability only manifests when the appliance runs specific configurations. Devices acting as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server are exposed. Other NetScaler ADC configurations may not be reachable by this exploit.
Impact
A successful exploit causes unpredictable or erroneous behavior in the appliance, culminating in a full denial of service. This means VPN sessions drop, remote access terminates, and all applications proxied through the appliance become unreachable. For organizations relying on NetScaler for remote workforce access, this can halt operations entirely.
CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score sits at 1.0%, indicating a moderate probability of broader exploitation in the next 30 days, though that figure climbs as public proof-of-concept code circulates.
Remediation
NetScaler has released a fix. Upgrade to the following versions:
- NetScaler ADC and Gateway 14.1-29.61 or later
If immediate patching is not possible, apply these mitigations:
- Remove affected virtual server types (SSL VPN, ICA Proxy, CVPN, RDP Proxy, AAA) until the patch is applied
- Restrict network access to management interfaces using firewall rules
- Monitor logs for anomalous traffic patterns targeting these services
The vendor advisory is available on the NetScaler security bulletin page. Also check breach reports for indicators of compromise and security news for follow-up coverage.
Security Insight
This is the second critical NetScaler memory overflow in under a year, signaling a pattern of memory-safety issues in the appliance’s networking stack. Attackers increasingly target edge devices because one bug yields access to an entire remote workforce. The active exploitation of CVE-2026-8452 within days of disclosure shows that threat actors automate attacks against Citrix/NetScaler infrastructure faster than many organizations can patch, reinforcing that edge devices should be treated as high-risk endpoints requiring rapid mitigation plans.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Public PoC References
Unverified third-party code
These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).
Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.
| Repository | Stars |
|---|---|
| watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452 CVE-2026-8452 PreAuth RCE | ★ 58 |
Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.
Related Advisories
Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos Era 300. Au...
Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and w...
A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulation of the argument File leads to stack-based buffe...
A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to out-of-bounds write. T...