CVE-2026-8452
NetScaler ADC/Gateway memory-overflow denial of service when configured as a Gateway (CVSS 8.8)
- Severity
- high
- Affected product
- Citrix NetScaler ADC/Gateway
- Affected versions
- Citrix NetScaler ADC/Gateway all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- EPSS
- 1% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-08-27
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Citrix NetScaler ADC/Gateway appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-27, CISA KEV (bleepingcomputer: 'CISA orders feds to patch Citrix NetScaler flaw'). Same version-gate wall as CVE-2025-5777 above: Citrix fixes this at build level while this appliance's version regex captures only major.minor, so an `lt` would call a patched 14.1 build vulnerable - a false positive. Advisory until a build-level version source exists. Only triggers when the box is configured as a Gateway (VPN vserver); the fingerprint cannot tell Gateway from ADC-only, so the row surfaces on either and the precondition stays in the title.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →