Unauthenticated memory buffer flaw in Citrix NetScaler ADC and Gateway exploited for remote code execution (CVE-2026-8452)
CISA added this flaw to the KEV catalog with a remediation deadline of 2026-08-29 amid multiple credible reports of in-the-wild exploitation, so teams that leave internet-facing NetScaler appliances unpatched this week are exposed to active attacks.
A memory buffer handling flaw in NetScaler ADC and NetScaler Gateway is reachable over the network without authentication or user interaction (CVSS 8.8, AV:N/PR:N/UI:N). Credible reporting describes it as enabling remote code execution on affected appliances, and at minimum it can take the service down. A related flaw, CVE-2026-8451, is fixed in the same advisory.
Affected: NetScaler ADC and Gateway 14.1 before 14.1-72.61; NetScaler ADC and Gateway 13.1 before 13.1-63.18; NetScaler ADC 13.1 FIPS and NDcPP before 13.1-37.272; NetScaler ADC 14.1 FIPS before 14.1-72.61
How to Test
Check the running NetScaler firmware build: any 14.1 build before 14.1-72.61, 13.1 build before 13.1-63.18, or 13.1 FIPS/NDcPP build before 13.1-37.272 is vulnerable. Treat internet-facing Gateway/ADC virtual servers as exposed and review appliance logs for anomalous crashes or unexpected requests since the June advisory.
How to Patch
Upgrade to NetScaler ADC/Gateway 14.1-72.61 or later, 13.1-63.18 or later, or 13.1 FIPS/NDcPP 37.272 or later per Citrix advisory CTX696604; there is no workaround listed, so prioritize the upgrade before the 2026-08-29 KEV due date.