Critical severity9.8NVD Advisory· Published Jun 30, 2026· Updated Jul 1, 2026
CVE-2026-8655
CVE-2026-8655
Description
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
Affected products
8cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*+ 3 more
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*range: >=13.1,<13.1-63.18
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*range: <13.1-37.272
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*range: <13.1-37.272
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1-66.68:*:*:*:fips:*:*:*
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*Range: >=13.1,<13.1-63.18
Patches
Vulnerability mechanics
References
1- support.citrix.com/support-home/kbsearch/articlenvdVendor Advisory
News mentions
0No linked articles in our index yet.