[KEV] CVE-2026-8452 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-8452 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-8452 is an improper memory-buffer operation restriction vulnerability in Citrix NetScaler ADC and NetScaler Gateway that can be triggered through the appliances' network-facing processing functionality and may cause denial of service.
Technical Detail
The flaw involves improper restriction of operations within the bounds of a memory buffer. An attacker may be able to send crafted input to a vulnerable NetScaler ADC or NetScaler Gateway instance and cause the affected service or appliance to become unavailable. The reported impact is denial of service; remote code execution, authentication bypass, privilege escalation, and data exposure have not been confirmed in the available information.
Exploitation Status
CISA has confirmed active exploitation in the wild. Exploit maturity is assessed as Operational, meaning exploitation methods are sufficiently developed for use in real-world attacks rather than being limited to a proof of concept. CVE-2026-8452 was added to CISA's Known Exploited Vulnerabilities catalog on August 26, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize remediation for all internet-facing and internally exposed Citrix NetScaler ADC and NetScaler Gateway appliances. Apply Citrix security updates and mitigations applicable to the deployed version as soon as they are available. As a CISA Known Exploited Vulnerability, affected federal civilian executive branch agencies must patch by September 16, 2026, or apply vendor-supported mitigations. Review appliance and network logs for unusual or malformed requests, unexpected service restarts, crashes, resource exhaustion, or availability interruptions; specific detection indicators have not yet been confirmed in the available information.