What it is
CVE-2026-8452 is an unauthenticated vulnerability affecting NetScaler ADC, Gateway. Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of...
Vulnerability report
ADC Denial of Service
NetScaler / ADC · affected before 72.61
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-8452 is an unauthenticated vulnerability affecting NetScaler ADC, Gateway. Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of...
Is it exploited?
Yes. Previdian sensors observed exploitation attempts with confirmed confidence. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
NetScaler / ADC affected before 72.61.
What should we do?
Patch immediately, validate internet-facing exposure, and monitor for matching requests.
Overview
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Previdian
Independent exploitation attestation added to the Previdian record.
Previdian sensor
First-party sensor telemetry confirms matching exploitation attempts.
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Previdian First | 2026-08-17 08:04 UTC |
| CISA | 2026-08-26 17:00 UTC |
| CVE | 2026-08-26 18:01 UTC |
| Daily CyberSecurity | 2026-08-27 02:30 UTC |
Operational indicators for this CVE are listed under Detection.
Sensor telemetry
Aggregate observations show the scale, recency, and distribution of activity without overstating sparse data.
56
Attempts observed
14
Unique attacker IPs
11
Attacker countries
CH · DE · HK · JP · NL · RU · SA · SG · TR · US · VN
1
Sensors observed
Exploitation attempts over the last 18 days
Daily events observed by Previdian sensors
Updated 02 Sep 2026
First observed 17 Aug 2026 · Last observed 01 Sep 2026
Pro adds sensor region and window summaries. Enterprise adds raw IPs, paths, User-Agents, and payloads.
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Raw values available in Pro and Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →Attacker IP indicators observed · available in Pro and Enterprise.
Sensor-derived attacker IP indicators are available to Pro and Enterprise accounts under Detection and through the Pro API.
Learn about Pro API accessRisk and context
CVSS v4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L
EPSS
1.6%
Recent mention · Daily CyberSecurity
CISA adds six exploited vulnerabilities to its KEV Catalog, including a Citrix NetScaler flaw and CVE-2026-8452, with active exploitation confirmed. Related Posts: Dell Cloud Disaster Recovery CVE-2026-70419 (CVSS 9.1) Allows Command Execution High-Severity TP-Link Kasa...
Read full advisoryCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Recent mention · Daily CyberSecurity
CISA Adds Six Exploited Vulnerabilities Including Citrix NetScaler FlawDaily CyberSecurity · 27 Aug 2026
CISA adds six exploited vulnerabilities to its KEV Catalog, including a Citrix NetScaler flaw and CVE-2026-8452, with active exploitation confirmed. Related Posts: Dell Cloud Disaster Recovery CVE-2026-70419 (CVSS 9.1) Allows Command Execution High-Severity TP-Link Kasa Vulnerability Requires Immediate Patch CVE-2026-53361: PoC Exploit Enables AF_UNIX Container Escape The post CISA Adds Six Exploited Vulnerabilities Including Citrix NetScaler Flaw appeared first on Daily CyberSecurity.
Recent mention · watchTowr
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))watchTowr · 14 Aug 2026
Suddenly, you’re in a room. You look around - oh, you’re surrounded by other new starters at your new job. Yes, it’s Monday, and you’re being onboarded.You know the drill - it’s the typical enterprise “please don’t be
These PoCs are unverified and could contain malware. Use at your own risk.
public · Created 2026-08-14 19:42:00 UTC
Timeline
Exploitation attested by an external source
Exploitation attested by an external source
Listed in the CISA Known Exploited Vulnerabilities catalog
Evidence-backed exploitation signal
Indicators of compromise recorded
Public proof-of-concept code published
Vulnerability disclosed publicly
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-8452
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-8452",
"confidence": "Confirmed",
"cvss_score": 8.8,
"cvss_estimated": false,
"epss_score": 0.01606,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": true
},
"sensor_telemetry": { "attempts": 56, "sensors": 1 }
}