Skip to content
COOEY

EXPOSURES › CVE-2026-8452

CVE-2026-8452

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-08-26 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-8452 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 92/100 exploited-in-wildrceunpatched

An unauthenticated attacker can execute arbitrary code as root on Citrix NetScaler ADC and Gateway appliances via CVE-2026-8452.

This memory buffer overflow allows remote code execution without authentication, enabling attackers to fully compromise the appliance. DIB organizations must immediately patch affected versions (14.1, 13.1, 14.1 FIPS, 13.1 FIPS) and monitor for exploitation, as the flaw is actively exploited in the wild and the PoC is publicly available.

Shame score — A critical RCE flaw in a widely deployed network appliance was actively exploited in the wild with a publicly available PoC, indicating severe negligence in patching and vulnerability management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Citrix for Government
Citrix
Authorized