CVE-2026-8655

EUVD-2026-40308
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 40.04%
Affected Products (NVD)
VendorProductVersion
citrixnetscaler_application_delivery_controller
𝑥
< 13.1-37.272
citrixnetscaler_application_delivery_controller
𝑥
< 13.1-37.272
citrixnetscaler_application_delivery_controller
13.1 ≤
𝑥
< 13.1-63.18
citrixnetscaler_application_delivery_controller
14.1 ≤
𝑥
< 14.1-72.61
citrixnetscaler_application_delivery_controller
14.1-66.68
citrixnetscaler_gateway
13.1 ≤
𝑥
< 13.1-63.18
citrixnetscaler_gateway
14.1 ≤
𝑥
< 14.1-72.61
𝑥
= Vulnerable software versions