{"api_version":"1","generated_at":"2026-07-01T17:13:52+00:00","cve":"CVE-2026-8655","urls":{"html":"https://cve.report/CVE-2026-8655","api":"https://cve.report/api/cve/CVE-2026-8655.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-8655","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-8655"},"summary":{"title":"Multiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of Service","description":"Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment","state":"PUBLISHED","assigner":"NetScaler","published_at":"2026-06-30 13:19:34","updated_at":"2026-07-01 15:52:05"},"problem_types":["CWE-119","CWE-119 CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer"],"metrics":[{"version":"4.0","source":"50a63c94-1ea7-4568-8c11-eb79e7c5a2b5","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"8.8","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:L","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.8,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:L","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnerabilityResponseEffort":"NOT_DEFINED"}},{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}}],"references":[{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604","name":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604","refsource":"50a63c94-1ea7-4568-8c11-eb79e7c5a2b5","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-8655","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8655","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"NetScaler","product":"ADC","version":"affected 14.1 72.61 patch","platforms":[]},{"source":"CNA","vendor":"NetScaler","product":"ADC","version":"affected 13.1 63.18 patch","platforms":[]},{"source":"CNA","vendor":"NetScaler","product":"ADC","version":"affected 14.1 FIPS 72.61 patch","platforms":[]},{"source":"CNA","vendor":"NetScaler","product":"ADC","version":"affected 13.1 FIPS and NDcPP 37.272 patch","platforms":[]},{"source":"CNA","vendor":"NetScaler","product":"Gateway","version":"affected 14.1 72.61 patch","platforms":[]},{"source":"CNA","vendor":"NetScaler","product":"Gateway","version":"affected 13.1 63.18 patch","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2026","cve_id":"8655","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"citrix","cpe5":"netscaler_application_delivery_controller","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"-","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"8655","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"citrix","cpe5":"netscaler_application_delivery_controller","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"fips","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2026","cve_id":"8655","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"citrix","cpe5":"netscaler_application_delivery_controller","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"ndcpp","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-8655","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-06-30T13:33:42.732082Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-119","description":"CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-30T13:33:48.823Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"ADC","vendor":"NetScaler","versions":[{"lessThan":"72.61","status":"affected","version":"14.1","versionType":"patch"},{"lessThan":"63.18","status":"affected","version":"13.1","versionType":"patch"},{"lessThan":"72.61","status":"affected","version":"14.1 FIPS","versionType":"patch"},{"lessThan":"37.272","status":"affected","version":"13.1 FIPS and NDcPP","versionType":"patch"}]},{"defaultStatus":"unaffected","product":"Gateway","vendor":"NetScaler","versions":[{"lessThan":"72.61","status":"affected","version":"14.1","versionType":"patch"},{"lessThan":"63.18","status":"affected","version":"13.1","versionType":"patch"}]}],"datePublic":"2026-06-30T12:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<span>Multiple Memory overflow vulnerabilities in&nbsp;</span><span>NetScaler ADC and NetScaler Gateway&nbsp;</span><span>leading to unpredictable or erroneous behavior and Denial of Service if&nbsp;</span><span>NetScaler ADC is configured as an LB of type Oracle&nbsp;</span><strong>OR&nbsp;</strong><span>NetScaler ADC is configured as a DNS Proxy&nbsp;</span><strong>OR</strong><span>&nbsp;</span><span>NetScaler ADC is configured as a DNS recursive resolver deployment</span><br>"}],"value":"Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment"}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.8,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:L","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"providerMetadata":{"dateUpdated":"2026-06-30T12:58:38.118Z","orgId":"50a63c94-1ea7-4568-8c11-eb79e7c5a2b5","shortName":"NetScaler"},"references":[{"url":"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604"}],"source":{"discovery":"UNKNOWN"},"title":"Multiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of Service","x_generator":{"engine":"Vulnogram 1.0.2"}}},"cveMetadata":{"assignerOrgId":"50a63c94-1ea7-4568-8c11-eb79e7c5a2b5","assignerShortName":"NetScaler","cveId":"CVE-2026-8655","datePublished":"2026-06-30T12:46:28.140Z","dateReserved":"2026-05-15T06:14:09.794Z","dateUpdated":"2026-06-30T13:33:48.823Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-06-30 13:19:34","lastModifiedDate":"2026-07-01 15:52:05","problem_types":["CWE-119","CWE-119 CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer"],"metrics":{"cvssMetricV40":[{"source":"50a63c94-1ea7-4568-8c11-eb79e7c5a2b5","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-30T13:33:42.732082Z","id":"CVE-2026-8655","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*","versionEndExcluding":"13.1-37.272","matchCriteriaId":"D8189708-5190-45E3-BF9A-7A429E87DFE7"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*","versionEndExcluding":"13.1-37.272","matchCriteriaId":"D93A5760-5C50-4786-B981-24A7B35C3055"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*","versionStartIncluding":"13.1","versionEndExcluding":"13.1-63.18","matchCriteriaId":"BC139A27-D7CE-4D92-9A1F-09713C4C9546"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*","versionStartIncluding":"14.1","versionEndExcluding":"14.1-72.61","matchCriteriaId":"0108075C-1047-449C-A707-F2532770C2AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:netscaler_application_delivery_controller:14.1-66.68:*:*:*:fips:*:*:*","matchCriteriaId":"A2BC089B-97D0-4FDB-A336-74409DCDC5E3"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*","versionStartIncluding":"13.1","versionEndExcluding":"13.1-63.18","matchCriteriaId":"962D2276-7285-41E2-A867-D464AE11677F"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*","versionStartIncluding":"14.1","versionEndExcluding":"14.1-72.61","matchCriteriaId":"1591FBCE-57DD-416F-A858-E898B0946AB6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"8655","Ordinal":"1","Title":"Multiple Memory overflow vulnerabilities leading to unpredictabl","CVE":"CVE-2026-8655","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"8655","Ordinal":"1","NoteData":"Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment","Type":"Description","Title":"Multiple Memory overflow vulnerabilities leading to unpredictabl"}]}}}