PT-2026-53880 · Citrix · Netscaler Gateway+1
CVE-2026-8452
·
Published
2026-06-30
·
Updated
2026-08-29
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NetScaler ADC versions prior to 14.1-72.61
NetScaler ADC versions prior to 13.1-63.18
NetScaler Gateway versions prior to 14.1-72.61
NetScaler Gateway versions prior to 13.1-63.18
Description
A memory overflow issue exists in NetScaler ADC and NetScaler Gateway when configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. While initially described as causing unpredictable behavior or denial of service, research has demonstrated that an unauthenticated remote attacker can achieve root-level remote code execution by sending crafted SAML data. This is achieved through memory corruption within the
nsppe process, which runs with root privileges, allowing the attacker to control the execution flow and deploy web shells. Real-world exploitation has been observed, with attackers executing reconnaissance commands such as id and echo. Approximately 22,000 NetScaler ADC appliances and 1,800 NetScaler Gateway systems are estimated to be exposed online.Recommendations
Update NetScaler ADC to version 14.1-72.61 or later.
Update NetScaler ADC to version 13.1-63.18 or later.
Update NetScaler Gateway to version 14.1-72.61 or later.
Update NetScaler Gateway to version 13.1-63.18 or later.
Restrict management interfaces from the internet to minimize the risk of exploitation.
Review the system for unexpected web shells, new files, unusual child processes, or suspicious outbound connections.
Fix
RCE
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netscaler Adc
Netscaler Gateway