Skip to main content

Proof-of-Concept Exploit Released for Citrix NetScaler ADC and NetScaler Gateway Vulnerability

Security researchers have demonstrated that CVE-2026-8452 could lead to remote code execution (RCE)

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security researchers have demonstrated that CVE-2026-8452 could lead to remote code execution (RCE)


Threat details

Proof-of-concept exploit for CVE-2026-8452

Security researchers have published a proof-of-concept exploit for CVE-2026-8452 demonstrating that CVE-2026-8452 may lead to unauthenticated remote code execution. The NHS England National CSOC assesses exploitation as highly likely.


Introduction

Citrix published a security advisory for a vulnerability affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Successful exploitation of CVE-2026-8452 could lead to denial-of-service (DoS) or remote code execution (RCE) when the appliance is configured as a Gateway or an AAA virtual server. 

  • CVE-2026-8452 - 'Memory overflow' vulnerability -  CVSSv4 score: 8.8

Note: While Citrix has described the impact as a denial-of-service condition, security researchers have published a proof of concept that demonstrates the vulnerability could lead to remote code execution (RCE).


Remediation advice

Affected organisations are encouraged to review Citrix advisory CTX696604 and apply the relevant update as soon as possible.



Last edited: 14 August 2026 1:06 pm