← All CVEs NewScan detects
highKEV

CVE-2026-8452

NetScaler ADC/Gateway memory-overflow denial of service when configured as a Gateway (CVSS 8.8)

Severity
high
Affected product
Citrix NetScaler ADC/Gateway
Affected versions
Citrix NetScaler ADC/Gateway all versions before the fix
CISA KEV
Listed as a known exploited vulnerability
EPSS
1% chance of exploitation in the next 30 days
Added to NewScan
2026-08-27
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Citrix NetScaler ADC/Gateway appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-27, CISA KEV (bleepingcomputer: 'CISA orders feds to patch Citrix NetScaler flaw'). Same version-gate wall as CVE-2025-5777 above: Citrix fixes this at build level while this appliance's version regex captures only major.minor, so an `lt` would call a patched 14.1 build vulnerable - a false positive. Advisory until a build-level version source exists. Only triggers when the box is configured as a Gateway (VPN vserver); the fingerprint cannot tell Gateway from ADC-only, so the row surfaces on either and the precondition stays in the title.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →