Citrix Netscaler Application Delivery Controller — CVE-2026-8655 (Critical)

Date Jun 30, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product Citrix · Netscaler Application Delivery Controller
CVE CVE-2026-8655
Critical vendor advisory CVE-2026-8655

Summary

Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 9.8) in Citrix Netscaler Application Delivery Controller. Patch or mitigate promptly. EPSS percentile: 30%.

Operator check

Review CVE-2026-8655 in your asset inventory. Apply patches per vendor guidance and verify Netscaler Application Delivery Controller is not exposed. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 30%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.