Description
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Memory overflow in Citrix NetScaler ADC and NetScaler Gateway can cause unpredictable or erroneous behavior, leading to a denial of service when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy). The flaw is a classic buffer overflow (CWE‑119), affecting the availability of the network service and potentially interrupting traffic for connected users.

Affected Systems

The vulnerability affects Citrix NetScaler ADC and NetScaler Gateway appliances. No specific affected firmware or software version was provided in the advisory, so all installations of these products should be examined.

Risk and Exploitability

With a CVSS score of 8.8 the vulnerability is considered high impact. EPSS data is not available and the issue is not listed in CISA’s KEV catalog. The flaw can likely be triggered remotely through network traffic when the appliance is set up as a gateway, potentially by attackers who can connect to the gateway services.

Generated by OpenCVE AI on June 30, 2026 at 17:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check with Citrix for a patch or firmware update that addresses the memory overflow in NetScaler ADC and Gateway.
  • Limit exposure of the NetScaler gateway services by restricting access to trusted networks or implementing strict firewall rules.
  • Monitor NetScaler logs and network traffic for signs of abnormal or repeated requests that may indicate exploitation attempts.

Generated by OpenCVE AI on June 30, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 30 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Netscaler
Netscaler adc
Netscaler gateway
Vendors & Products Netscaler
Netscaler adc
Netscaler gateway

Tue, 30 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120

Tue, 30 Jun 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120

Tue, 30 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 13:15:00 +0000

Type Values Removed Values Added
Description Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
Title Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NetScaler

Published:

Updated: 2026-06-30T13:37:04.747Z

Reserved: 2026-05-13T00:35:55.317Z

Link: CVE-2026-8452

cve-icon Vulnrichment

Updated: 2026-06-30T13:37:00.513Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-30T18:00:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer