Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5786 articles · 192433 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-8452KEVEXPLOITEDPATCHED
citrix · netscaler_application_delivery_controller

Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service

Description

A vulnerability has been found in Citrix NetScaler ADC and NetScaler Gateway classified as problematic. The affected element is an unknown function of the component Virtual Server Page. Performing a manipulation results in denial of service. This vulnerability was named CVE-2026-8452. The attack may be initiated remotely.

Affected Products

VendorProductVersions
citrixnetscaler_application_delivery_controller14.1, 13.1, 14.1 FIPS, 13.1 FIPS and NDcPP, 14.1, 13.1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
citrixnetscalercert_advisory90%
citrixnetscaler_gatewaycve_cpe95%

References

  • https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604

Related News (7 articles)

Tier B
CERT-FR16h ago
Bulletin d'actualité CERTFR-2026-ACT-035 (17 août 2026)
→ No new info (linked only)
Tier E
Hacker News3d ago
You're Back in the Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))
→ No new info (linked only)
Tier E
Reddit r/netsec3d ago
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) - watchTowr Labs
→ No new info (linked only)
Tier B
BSI Advisories47d ago
[NEU] [hoch] Citrix Systems NetScaler ADC und Gateway: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR47d ago
Multiples vulnérabilités dans les produits Citrix (01 juillet 2026)
→ No new info (linked only)
Tier B
CCCS Canada47d ago
Citrix security advisory (AV26-645)
→ No new info (linked only)
Tier C
VulDB48d ago
CVE-2026-8452 | Citrix NetScaler ADC/NetScaler Gateway Virtual Server Page denial of service (CTX696604)
→ No new info (linked only)
CVSS 3.17.5 HIGH
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
72.6163.1837.272
CWECWE-119
PublishedJun 30, 2026
Last enriched48d agov2
Trending Score122🔥
Source articles7
Independent6
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-53565
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges
Trending: 1
HIGHCVE-2026-53566EXP
Out-of-bounds memory read
Trending: 1
HIGHCVE-2026-13474EXP
Denial of service via malformed HTTP/2 requests
CRITICALCVE-2026-8451EXPKEV
Insufficient input validation leading to memory overread
CRITICALCVE-2026-10816
Arbitrary File Read (Unauthenticated)

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 30, 2026
Added to CISA KEV
Jun 30, 2026
Discovered by ZDM
Jun 30, 2026
Actively Exploited
Jun 30, 2026
Patch Available
Jun 30, 2026
Updated: description, severity, cvssEstimate, activelyExploited
Jun 30, 2026

Version History

v2
Last enriched 48d ago
v2Tier C48d ago

Updated description with new technical details, changed severity to HIGH, estimated CVSS score to 7.5, and noted that the exploit is not available but the vulnerability is actively exploited.

descriptionseveritycvssEstimateactivelyExploited
via VulDB
v148d ago

Initial creation