Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-8452KEVEXPLOITEDPATCHED
citrix · netscaler_application_delivery_controller

Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service

Description

A vulnerability has been found in Citrix NetScaler ADC and NetScaler Gateway classified as problematic. The affected element is an unknown function of the component Virtual Server Page. Performing a manipulation results in denial of service. This vulnerability was named CVE-2026-8452. The attack may be initiated remotely.

Affected Products

VendorProductVersions
citrixnetscaler_application_delivery_controller14.1, 13.1, 14.1 FIPS, 13.1 FIPS and NDcPP, 14.1, 13.1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
citrixnetscalercert_advisory90%
citrixnetscaler_gatewaycve_cpe95%

References

  • https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604

Related News (7 articles)

Tier B
CERT-FR7d ago
Bulletin d'actualité CERTFR-2026-ACT-035 (17 août 2026)
→ No new info (linked only)
Tier E
Hacker News9d ago
You're Back in the Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))
→ No new info (linked only)
Tier E
Reddit r/netsec9d ago
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) - watchTowr Labs
→ No new info (linked only)
Tier B
BSI Advisories53d ago
[NEU] [hoch] Citrix Systems NetScaler ADC und Gateway: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR54d ago
Multiples vulnérabilités dans les produits Citrix (01 juillet 2026)
→ No new info (linked only)
Tier B
CCCS Canada54d ago
Citrix security advisory (AV26-645)
→ No new info (linked only)
Tier C
VulDB54d ago
CVE-2026-8452 | Citrix NetScaler ADC/NetScaler Gateway Virtual Server Page denial of service (CTX696604)
→ No new info (linked only)
CVSS 3.17.5 HIGH
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
72.6163.1837.272
CWECWE-119
PublishedJun 30, 2026
Last enriched54d agov2
Trending Score46
Source articles7
Independent6
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-8451EXPKEV
Insufficient input validation leading to memory overread
Trending: 89
NONECVE-2026-19490
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
Trending: 53
NONECVE-2026-19489
CVE-2026-19489: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 thr
Trending: 40
NONECVE-2026-18751
Citrix Workspace App for Mac Security Bulletin for CVE-2026-18751
Trending: 20
NONECVE-2026-53565
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 30, 2026
Added to CISA KEV
Jun 30, 2026
Discovered by ZDM
Jun 30, 2026
Actively Exploited
Jun 30, 2026
Patch Available
Jun 30, 2026
Updated: description, severity, cvssEstimate, activelyExploited
Jun 30, 2026

Version History

v2
Last enriched 54d ago
v2Tier C54d ago

Updated description with new technical details, changed severity to HIGH, estimated CVSS score to 7.5, and noted that the exploit is not available but the vulnerability is actively exploited.

descriptionseveritycvssEstimateactivelyExploited
via VulDB
v154d ago

Initial creation