Proof-of-Concept Exploit Released for Citrix NetScaler ADC and NetScaler Gateway Vulnerability
Security researchers have demonstrated that CVE-2026-8452 could lead to remote code execution (RCE)
Summary
Security researchers have demonstrated that CVE-2026-8452 could lead to remote code execution (RCE)
Affected platforms
The following platforms are known to be affected:
Threat details
Proof-of-concept exploit for CVE-2026-8452
Security researchers have published a proof-of-concept exploit for CVE-2026-8452 demonstrating that CVE-2026-8452 may lead to unauthenticated remote code execution. The NHS England National CSOC assesses exploitation as highly likely.
Introduction
Citrix published a security advisory for a vulnerability affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Successful exploitation of CVE-2026-8452 could lead to denial-of-service (DoS) or remote code execution (RCE) when the appliance is configured as a Gateway or an AAA virtual server.
- CVE-2026-8452 - 'Memory overflow' vulnerability - CVSSv4 score: 8.8
Note: While Citrix has described the impact as a denial-of-service condition, security researchers have published a proof of concept that demonstrates the vulnerability could lead to remote code execution (RCE).
Remediation advice
Affected organisations are encouraged to review Citrix advisory CTX696604 and apply the relevant update as soon as possible.
Definitive source of threat updates
Last edited: 14 August 2026 1:06 pm