What it is
CVE-2026-8452 is an unauthenticated vulnerability affecting NetScaler ADC, Gateway. Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of...
Vulnerability report
ADC Denial of Service
NetScaler / ADC · affected before 72.61
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-8452 is an unauthenticated vulnerability affecting NetScaler ADC, Gateway. Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of...
Is it exploited?
Yes. Previdian sensors observed exploitation attempts with confirmed confidence. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
NetScaler / ADC affected before 72.61.
What should we do?
Patch immediately, validate internet-facing exposure, and monitor for matching requests.
Overview
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Previdian
Previdian independently recorded this as exploited after first seeing it in honeypot sensors.
Previdian sensor
Previdian first observed exploitation attempts targeting this vulnerability in our honeypot sensors.
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Previdian Sensors First | 2026-08-17 08:04 UTC |
| CISA | 2026-08-26 17:00 UTC |
| CVE | 2026-08-26 18:01 UTC |
| Daily CyberSecurity | 2026-08-27 02:30 UTC |
| Tenable Blog | 2026-09-27 10:21 UTC |
Operational indicators for this CVE are listed under Detection.
Sensor telemetry
Previdian sensors recorded exploitation attempts targeting this vulnerability. The cards and chart show volume, unique attackers, and daily activity.
105
Attempts observed
16
Unique attacker IPs
13
Attacker countries
CH · DE · HK · IE · IN · JP · NL · RU · SA · SG · TR · US · VN
2
Sensors observed
CVE-2026-8452 exploitation attempts over the last 55 days
Daily events observed by Previdian sensors
Updated 09 Oct 2026
First observed 17 Aug 2026 · Last observed 02 Oct 2026
Pro adds sensor region and window summaries. Enterprise adds raw IPs, paths, User-Agents, and payloads.
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →Attacker IP indicators observed · available in Pro and Enterprise.
Sensor-derived attacker IP indicators are available to Pro and Enterprise accounts under Detection and through the Pro API.
Learn about Pro API accessRisk and context
CVSS v4.0
Potential damage if exploited. Separate from whether attackers are using it.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L
EPSS
1.0%
Estimated chance of exploitation in the next 30 days. Previdian's warning comes from evidence, not this score.
Recent mention · Tenable Blog
There are reportedly two unpatched zero-day Citrix NetScaler vulnerabilities capable of enabling remote code execution that have been actively exploited in the wild, with no patches available at this time.Key takeawaysReports indicate that there are two critical zero-day...
Read full advisoryCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Recent mention · Tenable Blog
Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilitiesTenable Blog · 27 Sep 2026
There are reportedly two unpatched zero-day Citrix NetScaler vulnerabilities capable of enabling remote code execution that have been actively exploited in the wild, with no patches available at this time.Key takeawaysReports indicate that there are two critical zero-day vulnerabilities in Citrix NetScaler.The reports originate from a pre-notification sent out ahead of public disclosure, so there are currently no specific details about these flaws and no patches available.This post will be updated as new information becomes available.BackgroundTenable's Research Special Operations (RSO)...
Recent mention · RecordedFuture
August 2026 CVE LandscapeRecordedFuture · 08 Sep 2026
In August 2026, Insikt Group® identified 73 high-impact vulnerabilities that should be prioritized for remediation, 43 of which had a Very Critical Recorded Future Risk Score. This represents a 14% decrease from last month.
Recent mention · Daily CyberSecurity
CISA Adds Six Exploited Vulnerabilities Including Citrix NetScaler FlawDaily CyberSecurity · 27 Aug 2026
CISA adds six exploited vulnerabilities to its KEV Catalog, including a Citrix NetScaler flaw and CVE-2026-8452, with active exploitation confirmed. Related Posts: Dell Cloud Disaster Recovery CVE-2026-70419 (CVSS 9.1) Allows Command Execution High-Severity TP-Link Kasa Vulnerability Requires Immediate Patch CVE-2026-53361: PoC Exploit Enables AF_UNIX Container Escape The post CISA Adds Six Exploited Vulnerabilities Including Citrix NetScaler Flaw appeared first on Daily CyberSecurity.
Recent mention · watchTowr
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))watchTowr · 14 Aug 2026
Suddenly, you’re in a room. You look around - oh, you’re surrounded by other new starters at your new job. Yes, it’s Monday, and you’re being onboarded.You know the drill - it’s the typical enterprise “please don’t be
These PoCs are unverified and could contain malware. Use at your own risk.
public · Created 2026-08-14 19:42:00 UTC
Timeline
10:21 UTC
Exploitation attested by an external source
02:30 UTC
Exploitation attested by an external source
18:01 UTC
Exploitation attested by an external source
17:00 UTC
Listed in the CISA Known Exploited Vulnerabilities catalog
04:08 UTC
Indicators of compromise recorded
06:44 UTC
Evidence-backed exploitation signal
19:42 UTC
Public proof-of-concept code published
12:41 UTC
Vulnerability disclosed publicly
00:35 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-8452
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-8452",
"confidence": "Confirmed",
"cvss_score": 8.8,
"cvss_estimated": false,
"epss_score": 0.01011,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": true
},
"sensor_telemetry": { "attempts": 105, "sensors": 2 }
}