Description
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Multiple memory overflows exist in NetScaler ADC and NetScaler Gateway. These buffer overflows can result in unpredictable or erroneous behavior and ultimately cause a denial of service when the ADC operates as an Oracle load balancer, a DNS proxy, or a DNS recursive resolver. The primary impact is loss of availability for services that rely on the affected ADC instance. The vulnerability is a classic buffer overflow (CWE‑119). It is inferred that an attacker would need to target the ADC with specially crafted traffic to exploit the overflow.

Affected Systems

The affected products are Citrix NetScaler ADC and NetScaler Gateway. The advisory does not list specific firmware or software versions, so any deployment that places the ADC in one of the aforementioned configurations—Oracle load balancer, DNS proxy, or DNS recursive resolver—is potentially vulnerable. No other devices or versions were mentioned.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. EPSS is not available, suggesting no publicly known exploitation data yet but high potential risk. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need network access to the NetScaler device and the ability to target it in the specific configurations. It is inferred that the attack vector is network‑based, requiring an adversary to send malformed or oversized packets to the ADC to trigger the overflow, which could crash the service and cause a denial of service.

Generated by OpenCVE AI on June 30, 2026 at 18:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Citrix firmware update or patch that addresses the memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway.
  • If the patch is not yet available, avoid using the Oracle load balancer, DNS proxy, or DNS recursive resolver configurations on the ADC until the fix is applied.
  • Monitor device logs and network traffic for abnormal resets or crashes, and restrict traffic to the affected interfaces during remediation.

Generated by OpenCVE AI on June 30, 2026 at 18:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 30 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Netscaler
Netscaler adc
Netscaler gateway
Vendors & Products Netscaler
Netscaler adc
Netscaler gateway

Tue, 30 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
CWE-1698

Tue, 30 Jun 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
CWE-1698

Tue, 30 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 13:15:00 +0000

Type Values Removed Values Added
Description Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
Title Multiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of Service
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NetScaler

Published:

Updated: 2026-06-30T13:33:48.823Z

Reserved: 2026-05-15T06:14:09.794Z

Link: CVE-2026-8655

cve-icon Vulnrichment

Updated: 2026-06-30T13:33:35.229Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-30T18:15:15Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer