What it is
CVE-2026-8452 is an unauthenticated vulnerability affecting NetScaler ADC, Gateway. Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of...
Vulnerability report
ADC Denial of Service
NetScaler / ADC · affected before 72.61
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-8452 is an unauthenticated vulnerability affecting NetScaler ADC, Gateway. Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of...
Is it exploited?
Yes. Previdian sensors observed exploitation attempts with confirmed confidence. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
NetScaler / ADC affected before 72.61.
What should we do?
Patch immediately, validate internet-facing exposure, and monitor for matching requests.
Overview
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Previdian
Previdian independently recorded this as exploited after first seeing it in honeypot sensors.
Previdian sensor
Previdian first observed exploitation attempts targeting this vulnerability in our honeypot sensors.
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Previdian First | 2026-08-17 08:04 UTC |
| CISA | 2026-08-26 17:00 UTC |
| CVE | 2026-08-26 18:01 UTC |
| Daily CyberSecurity | 2026-08-27 02:30 UTC |
Operational indicators for this CVE are listed under Detection.
Sensor telemetry
Previdian sensors recorded exploitation attempts targeting this vulnerability. The cards and chart show volume, unique attackers, and daily activity.
73
Attempts observed
14
Unique attacker IPs
11
Attacker countries
CH · DE · HK · JP · NL · RU · SA · SG · TR · US · VN
1
Sensors observed
CVE-2026-8452 exploitation attempts over the last 27 days
Daily events observed by Previdian sensors
Updated 11 Sep 2026
First observed 17 Aug 2026 · Last observed 09 Sep 2026
Pro adds sensor region and window summaries. Enterprise adds raw IPs, paths, User-Agents, and payloads.
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →Attacker IP indicators observed · available in Pro and Enterprise.
Sensor-derived attacker IP indicators are available to Pro and Enterprise accounts under Detection and through the Pro API.
Learn about Pro API accessRisk and context
CVSS v4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L
EPSS
1.6%
Recent mention · RecordedFuture
In August 2026, Insikt Group® identified 73 high-impact vulnerabilities that should be prioritized for remediation, 43 of which had a Very Critical Recorded Future Risk Score. This represents a 14% decrease from last month.
Read full advisoryCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Recent mention · RecordedFuture
August 2026 CVE LandscapeRecordedFuture · 08 Sep 2026
In August 2026, Insikt Group® identified 73 high-impact vulnerabilities that should be prioritized for remediation, 43 of which had a Very Critical Recorded Future Risk Score. This represents a 14% decrease from last month.
Recent mention · Daily CyberSecurity
CISA Adds Six Exploited Vulnerabilities Including Citrix NetScaler FlawDaily CyberSecurity · 27 Aug 2026
CISA adds six exploited vulnerabilities to its KEV Catalog, including a Citrix NetScaler flaw and CVE-2026-8452, with active exploitation confirmed. Related Posts: Dell Cloud Disaster Recovery CVE-2026-70419 (CVSS 9.1) Allows Command Execution High-Severity TP-Link Kasa Vulnerability Requires Immediate Patch CVE-2026-53361: PoC Exploit Enables AF_UNIX Container Escape The post CISA Adds Six Exploited Vulnerabilities Including Citrix NetScaler Flaw appeared first on Daily CyberSecurity.
Recent mention · watchTowr
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))watchTowr · 14 Aug 2026
Suddenly, you’re in a room. You look around - oh, you’re surrounded by other new starters at your new job. Yes, it’s Monday, and you’re being onboarded.You know the drill - it’s the typical enterprise “please don’t be
These PoCs are unverified and could contain malware. Use at your own risk.
public · Created 2026-08-14 19:42:00 UTC
Timeline
Exploitation attested by an external source
Exploitation attested by an external source
Listed in the CISA Known Exploited Vulnerabilities catalog
Indicators of compromise recorded
Evidence-backed exploitation signal
Public proof-of-concept code published
Vulnerability disclosed publicly
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-8452
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-8452",
"confidence": "Confirmed",
"cvss_score": 8.8,
"cvss_estimated": false,
"epss_score": 0.01606,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": true
},
"sensor_telemetry": { "attempts": 73, "sensors": 1 }
}