← back
CVE-2026-8452highunder attackCWE-119

Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service

73Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 1.6%
from disclosure to weapon45 days
Published on NVDJun 30
1st PoC+45d
CISA KEV+57d
exploitation probability
1.6%top 26% of all CVEs
observed exploitation
yesCISA + VulnCheck
3 public exploit(s)
Action required by CISAfederal deadline: 2026-08-29

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

A memory overflow flaw in NetScaler ADC and Gateway can cause the system to behave unpredictably or crash when configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA server, disrupting service for users.

Technical detail

Memory overflow vulnerability in NetScaler ADC/Gateway when configured as SSL VPN, ICA Proxy, CVPN, RDP Proxy, or AAA virtual server allows memory corruption leading to unpredictable behavior, erroneous execution, and denial of service. Attack vectors depend on Gateway configuration and AAA service exposure.

Summary generated and translated by AI from the official description.
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.