PT-2026-53880 · Citrix · Netscaler Gateway+1

CVE-2026-8452

·

Published

2026-06-30

·

Updated

2026-08-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetScaler ADC versions prior to 14.1-72.61 NetScaler ADC versions prior to 13.1-63.18 NetScaler Gateway versions prior to 14.1-72.61 NetScaler Gateway versions prior to 13.1-63.18
Description A memory overflow issue exists in NetScaler ADC and NetScaler Gateway when configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. While initially described as causing unpredictable behavior or denial of service, research has demonstrated that an unauthenticated remote attacker can achieve root-level remote code execution by sending crafted SAML data. This is achieved through memory corruption within the nsppe process, which runs with root privileges, allowing the attacker to control the execution flow and deploy web shells. Real-world exploitation has been observed, with attackers executing reconnaissance commands such as id and echo. Approximately 22,000 NetScaler ADC appliances and 1,800 NetScaler Gateway systems are estimated to be exposed online.
Recommendations Update NetScaler ADC to version 14.1-72.61 or later. Update NetScaler ADC to version 13.1-63.18 or later. Update NetScaler Gateway to version 14.1-72.61 or later. Update NetScaler Gateway to version 13.1-63.18 or later. Restrict management interfaces from the internet to minimize the risk of exploitation. Review the system for unexpected web shells, new files, unusual child processes, or suspicious outbound connections.

Fix

RCE

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09281
CVE-2026-8452

Affected Products

Netscaler Adc
Netscaler Gateway