CVE-2026-8452Active Exploitation(citrix / netscaler_application_delivery_controller)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 45 mentions and remains active

Immediate actions

  • Patch citrix netscaler_application_delivery_controller systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-29. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-119

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netscaler_application_delivery_controller
  • netscaler_gateway

Threat summary

  • Active exploitation appears in 82 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 158 mentions across 29 observed days

What's happening

  • Active exploitation reported across 82 signals
  • Exploit tool or code specified in 16 signals
  • PoC mentioned or linked in 44 signals
  • Patch or workaround mentioned in 84 signals
  • Technical details provided in 101 signals
  • Peaked 10d ago at 45 mentions (2026-08-27); latest day: 3
  • 158 total mentions across 29 days

Affected systems

Vendors
Products
netscaler_application_delivery_controllernetscaler_gateway

1 version affected across 2 products

Deep dive

Activity timeline158 mentions / 29d
011233445Mentions · 2026-06-30: 1Mentions · 2026-07-01: 3Mentions · 2026-07-03: 1Mentions · 2026-07-04: 2Mentions · 2026-07-08: 1Mentions · 2026-07-09: 1Mentions · 2026-07-25: 1Mentions · 2026-08-14: 17Mentions · 2026-08-15: 6Mentions · 2026-08-16: 4Mentions · 2026-08-17: 13Mentions · 2026-08-18: 3Mentions · 2026-08-19: 1Mentions · 2026-08-21: 4Mentions · 2026-08-22: 1Mentions · 2026-08-24: 2Mentions · 2026-08-25: 2Mentions · 2026-08-26: 5Mentions · 2026-08-27: 45Mentions · 2026-08-28: 10Mentions · 2026-08-29: 5Mentions · 2026-08-30: 8Mentions · 2026-08-31: 10Mentions · 2026-09-01: 2Mentions · 2026-09-02: 4Mentions · 2026-09-05: 1Mentions · 2026-09-16: 1Mentions · 2026-09-27: 1Mentions · 2026-09-28: 3PoC Mentioned / Linked · 2026-08-14: 10PoC Mentioned / Linked · 2026-08-15: 4PoC Mentioned / Linked · 2026-08-16: 3PoC Mentioned / Linked · 2026-08-17: 8PoC Mentioned / Linked · 2026-08-18: 3PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-24: 2PoC Mentioned / Linked · 2026-08-25: 1PoC Mentioned / Linked · 2026-08-26: 1PoC Mentioned / Linked · 2026-08-27: 7PoC Mentioned / Linked · 2026-08-28: 1PoC Mentioned / Linked · 2026-08-30: 1PoC Mentioned / Linked · 2026-08-31: 1PoC Mentioned / Linked · 2026-09-05: 1Exploit Tool / Code · 2026-08-14: 4Exploit Tool / Code · 2026-08-15: 2Exploit Tool / Code · 2026-08-16: 1Exploit Tool / Code · 2026-08-17: 4Exploit Tool / Code · 2026-08-18: 2Exploit Tool / Code · 2026-08-21: 1Exploit Tool / Code · 2026-08-27: 1Exploit Tool / Code · 2026-08-29: 1Active Exploitation · 2026-07-01: 1Active Exploitation · 2026-08-14: 1Active Exploitation · 2026-08-17: 3Active Exploitation · 2026-08-19: 1Active Exploitation · 2026-08-21: 1Active Exploitation · 2026-08-22: 1Active Exploitation · 2026-08-24: 1Active Exploitation · 2026-08-26: 4Active Exploitation · 2026-08-27: 38Active Exploitation · 2026-08-28: 10Active Exploitation · 2026-08-29: 4Active Exploitation · 2026-08-30: 7Active Exploitation · 2026-08-31: 6Active Exploitation · 2026-09-01: 1Active Exploitation · 2026-09-02: 2Active Exploitation · 2026-09-05: 1Patch / Workaround · 2026-07-01: 2Patch / Workaround · 2026-07-03: 1Patch / Workaround · 2026-07-04: 2Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-07-25: 1Patch / Workaround · 2026-08-14: 7Patch / Workaround · 2026-08-15: 1Patch / Workaround · 2026-08-16: 1Patch / Workaround · 2026-08-17: 3Patch / Workaround · 2026-08-21: 2Patch / Workaround · 2026-08-24: 2Patch / Workaround · 2026-08-25: 1Patch / Workaround · 2026-08-26: 2Patch / Workaround · 2026-08-27: 26Patch / Workaround · 2026-08-28: 9Patch / Workaround · 2026-08-29: 5Patch / Workaround · 2026-08-30: 6Patch / Workaround · 2026-08-31: 7Patch / Workaround · 2026-09-01: 2Patch / Workaround · 2026-09-02: 2Patch / Workaround · 2026-09-05: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-04: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-25: 1Technical Details · 2026-08-14: 14Technical Details · 2026-08-15: 4Technical Details · 2026-08-16: 3Technical Details · 2026-08-17: 11Technical Details · 2026-08-18: 3Technical Details · 2026-08-21: 4Technical Details · 2026-08-22: 1Technical Details · 2026-08-24: 2Technical Details · 2026-08-25: 1Technical Details · 2026-08-26: 4Technical Details · 2026-08-27: 24Technical Details · 2026-08-28: 6Technical Details · 2026-08-29: 3Technical Details · 2026-08-30: 5Technical Details · 2026-08-31: 5Technical Details · 2026-09-01: 2Technical Details · 2026-09-02: 2Technical Details · 2026-09-05: 1Technical Details · 2026-09-16: 106-3007-0307-0807-2508-1508-1708-1908-2208-2508-2708-2908-3109-0209-1609-28
Signal classification6 categories
Active Exploitation
7750.0%
Patch
2214.3%
PoC
2214.3%
Disclosure
1912.3%
General
85.2%
Exploit
63.9%
Referenced assets137 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-301
Disclosure1
2026-07-013
Active Exploitation1Disclosure1Patch1
2026-07-031
Patch1
2026-07-042
Patch2
2026-07-081
Disclosure1
2026-07-091
Disclosure1
2026-07-251
Patch1
2026-08-1417
Disclosure3Exploit1General2Patch2PoC9
2026-08-156
Disclosure2Patch1PoC3
2026-08-164
Disclosure1Exploit1PoC2
2026-08-1713
Active Exploitation3Disclosure3Exploit2General2PoC3
2026-08-183
Exploit1PoC2
2026-08-191
Active Exploitation1
2026-08-214
Active Exploitation1Disclosure1Patch1PoC1
2026-08-221
Active Exploitation1
2026-08-242
Active Exploitation1PoC1
2026-08-252
Disclosure1Patch1
2026-08-265
Active Exploitation3Exploit1Patch1
2026-08-2745
Active Exploitation36Disclosure2General1Patch5PoC1
2026-08-2810
Active Exploitation9Disclosure1
2026-08-295
Active Exploitation4Patch1
2026-08-308
Active Exploitation7General1
2026-08-3110
Active Exploitation6General1Patch3
2026-09-012
Active Exploitation1Patch1
2026-09-024
Active Exploitation2General1Patch1
2026-09-051
Active Exploitation1
2026-09-161
Disclosure1
Full discourse20 posts
  • watchTowr@watchtowrcyber
    PoC

    You're back in the room, trapped with us - and a Citrix NetScaler Pre-Auth RCE (CVE-2026-8452) Enjoy... https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/

    Post summary

    The post announces a Citrix NetScaler pre‑authentication RCE vulnerability (CVE‑2026‑8452) and provides a link to a lab site, indicating a Proof of Concept is available.

    71041131813699.0K
    13.1K followersView on X
  • cr3ghost@cr3ghost
    PoC

    Citrix admins, your weekend plans just changed. CVE-2026-8452 was disclosed as a NetScaler memory overflow / DoS. Now @watchtowrcyber has dropped a Pre-Auth RCE PoC. Internet-facing edge appliances. No authentication. RCE. https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452 #ReverseEngineering #VulnerabilityResearch #Infosec

    Post summary

    The post announces that CVE-2026-8452 is a NetScaler memory overflow leading to a remote code execution vulnerability, and a proof‑of‑concept exploit is publicly available on GitHub.

    360021712617.7K
    8.3K followersView on X
  • ThreatWire@ThreatWire_
    Exploit

    🚨 CRITICAL: Public exploit code is now available for CVE-2026-8452, a critical Citrix NetScaler pre-auth vulnerability. The SAML-related heap overflow can be weaponized for unauthenticated remote code execution as root, resulting in full device compromise. Admins should patch affected NetScaler ADC/Gateway appliances immediately. 🔗 https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452 #Citrix #NetScaler #CVE #RCE #PoC #CyberSecurity #Infosec

    Post summary

    Public exploit code for CVE‑2026‑8452, a critical SAML‑related heap overflow in Citrix NetScaler, has been released on GitHub, enabling unauthenticated RCE as root; operators are urged to patch immediately.

    050018110530.6K
    1.6K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ CISA added six exploited flaws to KEV, spanning NetScaler, Linux, SQL Server, Red Hat, and AjaxPro. NetScaler CVE-2026-8452 stands out: web shells were dropped, with 36 exploitation attempts from 12 IPs in 12 days. CISA also says injection flaws dominate recent CVEs, while AI is being used to automate exploitation. Read: https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html

    Post summary

    CISA reports six KEV-listed flaws, including NetScaler CVE‑2026‑8452, are actively exploited—36 attack attempts over 12 days—highlighting injection dominance and AI‑driven exploitation.

    4210991832.1K
    2.4M followersView on X
  • I'M H4CK3R 42@luckyhacker43
    Exploit

    🔥 CVE-2026-8452: Pre‑Auth RCE in Citrix NetScaler – Fully weaponized. watchTowr just dropped the bomb. One‑liner gets you root shell on unpatched Netscaler appliances – no creds needed. 📌 Exploit: python3 http://watchTowr-vs-Citrix-Netscaler-PreAuth-RCE.py --target https://<target>:9443/ 📌 Result: Webshell at /vpn/theme/x.php?o=uname+-a;id → euid=0(root) egid=0(wheel) – full box takeover This isn't a theory. This is production‑ready code right now. 🛑 If you run Citrix NetScaler: · Patch immediately · Check logs for /vpn/theme/x.php · Assume compromise if unpatched 👀 The script is public – attackers will be scanning within hours. 🔗 Repo: http://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452 This is why patch Tuesday exists. Share now to save your infra. #CVE20268452 #Citrix #NetScaler #RCE #InfoSec #CyberSecurity #ZeroDay #PatchNow #RedTeam #BugBounty

    Post summary

    The post announces CVE-2026-8452, shares a ready‑to‑run Python exploit script, and urges immediate patching, but does not confirm that the vulnerability has already been actively exploited.

    011064283.2K
    4.7K followersView on X
  • watchTowr@watchtowrcyber
    PoC

    https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

    Post summary

    The GitHub repository hosts a proof‑of‑concept exploit for Citrix Netscaler’s pre‑authentication remote code execution vulnerability CVE‑2026‑8452, providing both exploit code and technical details but no evidence of widespread active exploitation.

    024149135.6K
    13.1K followersView on X
  • Ryan Dewhurst@ethicalhack3r
    Active Exploitation

    This morning we started seeing exploitation for CVE-2026-8452 (Citrix Netscaler PreAuthRCE). The attackers were dropping a web shell named "x.php" and "z.php", and running discovery commands, like "id" and "echo". So far we have seen three unique IPs, from three different countries.

    Post summary

    Reports indicate that CVE-2026-8452 is being actively exploited, with attackers deploying web shells and running discovery commands from a handful of unique IPs. While evidence of real-world exploitation exists, the scope appears limited so far.

    211050154.7K
    21.2K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 Citrix NetScaler ADC / Gateway'de CVE-2026-8452 için Pre-Auth RCE PoC'u yayınlandı! Araştırmacılar bu açığı root seviyesinde RCE'ye dönüştürmeyi başarmış. Açığın, NetScaler'ın root yetkileriyle çalışan nsppe adlı packet-processing engine'ine ulaşabildiği gösterilmiş. https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

    Post summary

    A pre‑authentication remote code execution proof‑of‑concept has been published for CVE‑2026‑8452 on Citrix NetScaler, demonstrating root‑level RCE via the nsppe packet‑processing engine.

    114039212.8K
    2.4K followersView on X
  • I'M H4CK3R 42@luckyhacker43
    PoC

    Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?) by watchTowr Team 🤯🔥 👨‍💻 Sina Kheirkhah (x/sinsinology) 🔗 https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/ 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-8452 https://t.me/luckyhacker42 https://t.co/Ovxzaow5bk

    Post summary

    This post announces a newly disclosed Citrix NetScaler pre‑auth remote code execution vulnerability (CVE‑2026‑8452) and shares a proof‑of‑concept via a public link, but it does not mention active exploitation, patches, or debunking.

    09146122.6K
    4.7K followersView on X
  • I'M H4CK3R 42@luckyhacker43
    Disclosure

    Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?) by watchTowr Team 🤯🔥 👨‍💻 Sina Kheirkhah (x/sinsinology) 🔗 https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/ 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-8452 Join team 👉https://t.me/luckyhacker42 https://t.co/u9bj5DbrXW

    Post summary

    The tweet announces CVE-2026-8452, a Citrix NetScaler Pre-Auth Remote Code Execution vulnerability, by the watchTowr Team, linking to an external blog post and NVD entry. It provides basic technical identification but no exploit code, PoC, active exploitation evidence, or remediation guidance within the tweet itself.

    08042112.2K
    4.7K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ Detection Artifact Generator for Citrix NetScaler CVE-2026-8452 GitHub: https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452 https://t.co/IQITw4hirh

    Post summary

    The tweet shares a GitHub repo that hosts a detection‑artifact generator aimed at Citrix NetScaler CVE‑2026‑8452, indicating code presence but no mention of active exploitation or patching.

    170351610.1K
    240.1K followersView on X
  • Co11ateral@co11ateral
    Disclosure

    Citrix NetScaler Pre-Auth RCE (CVE-2026-8452) Unauthenticated heap overflow in SAML signature canonicalization. An oversized PrefixList inside the <ds:SignedInfo> InclusiveNamespaces element overflows a fixed-size buffer, corrupting adjacent nsb chunk metadata. This yields a write-what-where primitive (controlled memcpy src/dst), allowing overwrite of tx_pkt_complete_fptr and jump to attacker shellcode on the executable heap. Results in root RCE when NetScaler is configured as SAML SP or IdP. Affected: NetScaler ADC/Gateway 14.1 < 14.1-72.61 and 13.1 < 13.1-63.18 https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

    Post summary

    The post discloses a new Citrix NetScaler pre‑auth RCE (CVE‑2026‑8452), outlines its technical details, and shares a PoC repository, but does not mention exploitation, patches, or a false positive.

    04132204.4K
    12.1K followersView on X
  • I'M H4CK3R 42@luckyhacker43

    Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?) by watchTowr Team 🤯🔥 👨‍💻 Sina Kheirkhah (x/sinsinology) 🔗 https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/ 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-8452 Get more resources and learning materials 👉 https://t.me/luckyhacker42 https://t.co/EiSDsvt8mX

    07025112.0K
    4.7K followersView on X
  • I'M H4CK3R 42@luckyhacker43
    PoC

    Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?) by watchTowr Team 🤯🔥 👨‍💻 Sina Kheirkhah (x/sinsinology) 🔗 https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/ 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-8452 🔗 Join team 👉https://t.me/luckyhacker42 https://t.co/E5AEsL2o97

    Post summary

    WatchTowr team announces a pre‑authentication RCE in Citrix NetScaler (CVE‑2026‑8452) and points to a lab page likely containing a proof‑of‑concept, but no exploit code, active exploitation, patch, or detailed technical data is provided.

    02027122.3K
    4.7K followersView on X
  • N45HT@N45HTOfficial
    PoC

    Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?) by watchTowr Team 🤯🔥 👨‍💻 Sina Kheirkhah (x/sinsinology) 🔗 https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/ 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-8452 https://t.co/78VUkZfi9q

    Post summary

    The post references a new Citrix NetScaler Pre‑Auth RCE (CVE‑2026‑8452) and links to a blog that presumably contains a proof‑of‑concept, but it lacks detail on active exploitation, patches, or specific exploit code.

    02123111.5K
    676 followersView on X
  • Dark Web Informer@DarkWebInformer

    citrixInspector: Passively identify Citrix ADC / NetScaler ADC &amp; Gateway builds and check for known vulnerabilities, including CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and KEV-listed CVE-2026-88771/88772. GitHub: https://github.com/securekomodo/citrixInspector https://t.co/UXQoHjAzb4

    04020126.5K
    240.6K followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-8452 Vendor: NetScaler Product: ADC Description: Unauthenticated heap overflow in SAML signature canonicalization. An oversized PrefixList inside the <ds:SignedInfo> InclusiveNamespaces element overflows a fixed-size buffer, corrupting adjacent nsb chunk metadata. This yields a write-what-where primitive (controlled memcpy src/dst), allowing overwrite of tx_pkt_complete_fptr and jump to attacker shellcode on the executable heap. Results in root RCE when NetScaler is configured as SAML SP or IdP. Link: https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452 #dbugs_vuln

    Post summary

    PoC and functional exploit code for CVE‑2026‑8452 have been released, enabling a root RCE through an unauthenticated heap overflow in NetScaler’s SAML processing.

    0102172.0K
    3.6K followersView on X
  • Bishop Fox@bishopfox
    Patch

    How do you verify a NetScaler memory-corruption patch without crashing the box? CVE-2026-8452 has a measurable behavioral difference between patched and unpatched SAML endpoints. One or two ordinary requests. No crash required. https://t.co/3fA24PzfcZ

    Post summary

    The tweet describes a simple, non‑crashing method to confirm the NetScaler CVE‑2026‑8452 patch by observing behavioral differences in SAML endpoints, while providing a link to a verification resource.

    1501441.5K
    26.3K followersView on X
  • JPCERTコーディネーションセンター@jpcert
    PoC

    NetScaler ADCおよびNetScaler Gatewayにおけるリモートコード実行につながる脆弱性(CVE-2026-8452)に関する注意喚起を公開。本脆弱性関連とみられるWebshellが設置可能な概念実証コードが公開されました。速やかに脆弱性への対策や侵害調査を実施してください。^MH https://www.jpcert.or.jp/at/2026/at260024.html

    Post summary

    A security alert announces CVE-2026-8452, a remote code‑execution issue in NetScaler ADC/Gateway, noting that a proof‑of‑concept web‑shell deployment code has been released and urges prompt countermeasures.

    0701526.4K
    34.3K followersView on X
  • FOFA@fofabot
    PoC

    ⚠️⚠️ CVE-2026-8452 (CVSS 8.8): Pre-authentication heap overflow in Citrix NetScaler ADC/Gateway SAML canonicalization allows unauthenticated attackers to achieve root-level remote code execution. 🔗FOFA Link: https://en.fofa.info/result?qbase64=dGl0bGU9Ik5ldFNjYWxlciI= 🎯51.3K+ Results are found on http://en.fofa.info in the past year. FOFA Query: title="NetScaler" PoC: https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/ 🔖Refer: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post discloses a pre-authentication RCE in Citrix NetScaler, shares a PoC link, and cites a Citrix support article likely containing patch information, with no evidence of active exploitation.

    0401131.9K
    14.8K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller14.1-66.68--
Appcitrixnetscaler_gateway---

Explore more