EXPOSURES › CVE-2026-8452
CVE-2026-8452
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated attacker can execute arbitrary code as root on Citrix NetScaler ADC and Gateway appliances via CVE-2026-8452.
This memory buffer overflow allows remote code execution without authentication, enabling attackers to fully compromise the appliance. DIB organizations must immediately patch affected versions (14.1, 13.1, 14.1 FIPS, 13.1 FIPS) and monitor for exploitation, as the flaw is actively exploited in the wild and the PoC is publicly available.
Shame score — A critical RCE flaw in a widely deployed network appliance was actively exploited in the wild with a publicly available PoC, indicating severe negligence in patching and vulnerability management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
| PRODUCT | STATUS |
|---|---|
| Citrix for Government Citrix |
Authorized |