← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 14, 2026 · 13:32via Cyber Security News

Citrix NetScaler Heap Overflow Flaw Lets Remote Attackers Execute Code as Root – PoC Released

Brief

A working proof-of-concept (PoC) exploit demonstrating how a pre-authentication heap overflow in Citrix NetScaler ADC and NetScaler Gateway can be turned into unauthenticated root-level remote code execution (RCE).

The vulnerability was originally addressed in Cloud Software Group’s June 30 security bulletin CTX696604, where Citrix described CVE-2026-8452 as a memory overflow that could result in denial-of-service (DoS) or “unpredictable behavior.”

However, independent analysis confirms that the flaw is far more severe, granting remote attackers direct control over the core packet-processing engine that runs with root privileges.

Addressing recurring Citrix NetScaler vulnerabilities remains essential for securing enterprise perimeter infrastructure.

Read more on Cyber Security News