Multiple Memory Overflow Vulnerabilities in NetScaler ADC and Gateway
Article Content
- •CVE-2026-8655 and CVE-2026-8452 are critical memory overflow vulnerabilities in NetScaler.
- •Affected systems include NetScaler ADC and Gateway under specific configurations.
- •Denial of Service is a potential outcome if these vulnerabilities are exploited.
Two critical memory overflow vulnerabilities have been identified in NetScaler ADC and NetScaler Gateway, both published on July 2, 2026. CVE-2026-8655 affects configurations as an Oracle load balancer, DNS proxy, or DNS recursive resolver, leading to unpredictable behavior and potential Denial of Service (DoS). CVE-2026-8452 impacts configurations as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, also resulting in similar issues. These vulnerabilities could allow attackers to exploit the affected systems, causing significant disruptions. Organizations using these configurations are urged to assess their systems for vulnerabilities and apply necessary mitigations. The current status is that both vulnerabilities are acknowledged, but no patches have been mentioned yet.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…