Critical Citrix NetScaler Memory-Overflow Vulnerability

Citrix initially described it as capable of causing unpredictable behavior or denial-of-service conditions, while research by WatchTowr[1] demonstrated that it can potentially be exploited for unauthenticated remote code execution. For successful exploitation it must be a Citrix NetScaler running a vulnerable version and must be configured as either a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or a AAA virtual server.

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

CVE

CVE-2026-8452

Affected Products

NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-72.61
NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.18
NetScaler ADC FIPS BEFORE 14.1-72.61 FIPS
NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.272

Exploitation

CVE-2026-8452 has recently been added to the CISA database of known exploited vulnerabilities[2].

Recommended Actions

Truesec recommends upgrading to the patched NetScaler firmware versions.

To determine whether the appliance meets the preconditions, inspect the NetScaler configuration and look for the following strings[3]:

  • An Auth Server (AAA Vserver): add authentication vserver .*
  • A Gateway (VPN Vserver, ICA Proxy, CVPN, RDP Proxy) : add vpn vserver .*

References

[1] https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452
[2] https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog
[3] https://support.citrix.com/external/article/CTX696604/netscaler-adc-and-netscaler-gateway-secu.html

The post Critical Citrix NetScaler Memory-Overflow Vulnerability appeared first on Truesec.

Article Link: Critical Citrix NetScaler Memory-Overflow Vulnerability - Truesec