Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
References
| Link | Resource |
|---|---|
| https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
01 Jul 2026, 15:52
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 - Vendor Advisory | |
| CPE | cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:* cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1-66.68:*:*:*:fips:*:*:* cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:* cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:* cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| First Time |
Citrix
Citrix netscaler Gateway Citrix netscaler Application Delivery Controller |
30 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-119 |
30 Jun 2026, 13:19
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-30 13:19
Updated : 2026-07-01 15:52
NVD link : CVE-2026-8655
Mitre link : CVE-2026-8655
CVE.ORG link : CVE-2026-8655
JSON object : View
Products Affected
citrix
- netscaler_gateway
- netscaler_application_delivery_controller
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
