CISA KEV Alert: Actively Exploited Citrix NetScaler ADC/Gateway Memory Buffer Flaw (CVE-2026-8452)
What happened
CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities (KEV) catalog on 2026-08-26. According to Citrix, the flaw affects NetScaler ADC and NetScaler Gateway and is described as an improper restriction of operations within the bounds of a memory buffer, which could lead to denial of service. CISA's KEV listing indicates the vulnerability is being actively exploited in the wild; a CVSS score has not yet been published, and there is no confirmation at this time of use in known ransomware campaigns.
Why it matters
NetScaler ADC and Gateway are widely deployed as internet-facing load balancers and VPN/remote-access gateways, making them a high-value target for attackers seeking initial footholds or disruption of critical access infrastructure. A memory-safety bug leading to denial of service on these devices could take down VPN access, application delivery, or authentication flows for an organization — and Citrix NetScaler has a history of being targeted at scale once exploitation details circulate. KEV inclusion means federal agencies are on a mandated remediation timeline, and this should be treated as a high-priority patching item by any organization running NetScaler ADC/Gateway.
What defenders should do now
- Identify all NetScaler ADC and NetScaler Gateway instances in your environment and check them against Citrix's advisory (CTX696604) for affected versions and available fixes.
- Apply vendor-supplied patches or mitigations as soon as they are available; treat internet-facing NetScaler appliances as priority assets.
- Monitor NetScaler appliance health, crash logs, and process restarts for signs of instability or crash-looping consistent with a memory-corruption DoS attempt.
- Review network and access logs for anomalous or malformed traffic patterns directed at management and gateway interfaces.
- Restrict management interface exposure and ensure NetScaler devices are not unnecessarily reachable from the public internet.
Developing story
Details on this vulnerability are still emerging — specifics of the exploitation observed by CISA, affected version ranges, and a finalized CVSS score have not yet been fully disclosed. This post will be treated as developing intel; check Citrix's official advisory for the latest guidance: CTX696604.