Summary
CVE-2026-8452 is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway, scored 8.8 (HIGH) under CVSS 4.0. The flaw affects appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server — the standard deployment mode for NetScaler Gateway — and can be triggered by unauthenticated remote attackers with no user interaction required. Exploitation may result in unpredictable or erroneous system behavior and Denial of Service; the CVSS 4.0 vector assigns High confidentiality impact (VC:H) and High availability impact (VA:H) on the vulnerable component.
Technical details
- Root cause: Memory overflow in the NetScaler ADC/Gateway software stack, present when the Gateway or AAA virtual server function is enabled
- Trigger conditions: Appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server; this is the primary, intended deployment mode for NetScaler Gateway and is not a niche configuration
- Attack vector: Remotely exploitable over the network (AV:N); no authentication required (PR:N); no user interaction needed (UI:N); exploitable under low attack complexity (AC:L) with no special attack requirements (AT:N)
- Impact: Unpredictable or erroneous behavior and Denial of Service; the CVSS 4.0 base vector records High confidentiality impact (VC:H) and High availability impact (VA:H) on the vulnerable component, alongside Low integrity impact (VI:L)
Affected software
- NetScaler ADC 14.1 before 14.1-72.61
- NetScaler ADC 13.1 before 13.1-63.18
- NetScaler ADC 14.1 FIPS before 14.1-72.61
- NetScaler ADC 13.1 FIPS and NDcPP before 13.1-37.272
- NetScaler Gateway 14.1 before 14.1-72.61
- NetScaler Gateway 13.1 before 13.1-63.18
Severity
CVSS 4.0 base score: 8.8 (HIGH)
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L
(CVSS v3.1 score has not yet been published by NVD as of June 30, 2026.)
Mitigation and recommended actions
Citrix strongly recommends upgrading to a fixed build immediately:
- NetScaler ADC 14.1 → upgrade to 14.1-72.61 or later
- NetScaler ADC 13.1 → upgrade to 13.1-63.18 or later
- NetScaler ADC 14.1 FIPS → upgrade to 14.1-72.61 or later
- NetScaler ADC 13.1 FIPS / NDcPP → upgrade to 13.1-37.272 or later
- NetScaler Gateway 14.1 → upgrade to 14.1-72.61 or later
- NetScaler Gateway 13.1 → upgrade to 13.1-63.18 or later
If immediate patching is not feasible, restrict network access to Gateway and AAA virtual server interfaces from untrusted networks as a temporary measure until the patch can be applied.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

