Site icon VMVirtualMachine.com

Citrix NetScaler Heap Overflow Flaw Lets Remote Attackers Execute Code as Root – PoC Released

Citrix NetScaler Heap Overflow Flaw Lets Remote Attackers Execute Code as Root – PoC Released

By Guru Baran
Publication Date: 2026-08-14 13:32:00

A working proof-of-concept (PoC) exploit demonstrating how a pre-authentication heap overflow in Citrix NetScaler ADC and NetScaler Gateway can be turned into unauthenticated root-level remote code execution (RCE).

The vulnerability was originally addressed in Cloud Software Group’s June 30 security bulletin CTX696604, where Citrix described CVE-2026-8452 as a memory overflow that could result in denial-of-service (DoS) or “unpredictable behavior.”

However, independent analysis confirms that the flaw is far more severe, granting remote attackers direct control over the core packet-processing engine that runs with root privileges.

Addressing recurring Citrix NetScaler vulnerabilities remains essential for securing enterprise perimeter infrastructure.

WatchTowr Labs said in a report shared with Cyber Security News (CSN) that the flaw is reachable without credentials and can be steered into control of nsppe, the packet-processing engine that already runs as…

Exit mobile version