GPU VulnDB

Database/Control plane, storage & DevOps

Citrix NetScaler ADC/Gateway: memory overflow in Gateway and AAA vservers causes denial of service

CVE-2026-8452Control plane, storage & DevOpsKnown exploitedcurated

Impact

A memory overflow in the appliance leads to unpredictable or erroneous behaviour and denial of service when it is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server. Where NetScaler is the remote-access path into a datacenter, losing it takes operators and tenants out of the environment at exactly the moment they need in, and the appliance is a single choke point rather than something you can shed load from. CISA lists the flaw as exploited in the wild. The CVSS 4.0 vector also scores high confidentiality impact, though the description itself only claims erratic behaviour and DoS - treat the confidentiality exposure as unconfirmed by the vendor text.

Who can reach it

Anyone who can reach the Gateway or AAA virtual server IP, unauthenticated. These vservers are normally published to the internet. Appliances not configured as a Gateway or AAA vserver are not affected.

What to do

Move to a fixed build per Citrix CTX696604. This is an appliance image upgrade plus reboot, not a package update, so schedule it per node of an HA pair and fail over between them; expect established sessions to drop. If an appliance runs neither a Gateway nor an AAA vserver, it is out of scope and needs no window. The record does not name the fixed build numbers - take them from CTX696604 rather than assuming the 14.1-66.68 version string in the CVE data is the fix.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.