The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record
Check whether your deployment is NetScaler ADC or NetScaler Gateway, and confirm if it is configured as an Oracle load balancer, a DNS Proxy, or a DNS recursive resolver.
Check your current NetScaler software version (Administration UI or system/version page).
Upgrade to a fixed version: for ADC or Gateway, move to 72.61 (or 63.18 / 37.272 as applicable), and for the corresponding ADC/Gateway branches ensure your target line matches the vendor’s fixed versions.
If you cannot upgrade right away, reduce exposure by disabling the affected roles/features that match your configuration (Oracle LB, DNS Proxy, or DNS recursive resolver) until patched.
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
In plain language
Written by AI from the record
CVE-2026-8655 is a NetScaler ADC/Gateway bug that an outsider can trigger over the network to crash the service or make it behave unpredictably; you should update if you run NetScaler as an Oracle load balancer or DNS proxy/recursive resolver.
CVE-2026-8655 is a set of unauthenticated, network-triggerable memory overflow flaws (CWE-119) in netscaler application delivery controller and netscaler gateway; exploitation causes unpredictable/erroneous behavior or Denial of Service when NetScaler ADC is configured as an Oracle LB, DNS Proxy, or DNS recursive resolver.
If you're affected
Service outages for customer traffic
Unreliable DNS resolution
Gateway/LB instability
Potential disruption of business operations
What is it
This vulnerability is like a weakness in NetScaler’s “core memory handling” that can be triggered from the network. Depending on how you’ve set up NetScaler (especially for DNS proxy/recursive DNS or Oracle load balancing), it can cause the service to crash or start behaving incorrectly, which can break access to your applications or name resolution for your customers.
Who is affected
This matters if you run netscaler application delivery controller or netscaler gateway and you use it in one of these ways: as an Oracle load balancer, a DNS Proxy, or a DNS recursive resolver. Because the trigger does not require authentication or user interaction, exposure depends mainly on whether your NetScaler is reachable and providing those network services.
Only consider it a direct risk if your NetScaler is reachable over the network in those roles (Oracle LB / DNS proxy / DNS recursive resolver).
How urgent is it
Treat this as a medium-high priority: it can be triggered remotely over the network and can lead to Denial of Service or erratic behavior, which can disrupt customer traffic. While the provided information does not show confirmed exploitation in the wild, the vulnerability is critical in severity and the fix is available.
If you use the affected roles (Oracle LB or DNS proxy/recursive resolver), prioritize patching on your next maintenance window or sooner.
What to do — in detail
Confirm exposure conditions
Determine whether the device is netscaler application delivery controller (ADC) or netscaler gateway.
Verify your configuration role:
Oracle load balancer, OR
DNS Proxy, OR
DNS recursive resolver.
Check whether the service is reachable from external networks (for example, Internet-facing VIPs/IPs that serve those functions).
Identify your current software version
Record the exact NetScaler ADC/Gateway version currently installed.
Compare it to the vendor “fixed in” versions listed for your product.
Upgrade to the fixed release
ADC fixed in 72.61, 63.18, and 37.272 (choose the upgrade path that matches your branch/support requirements).
Gateway fixed in 72.61 and 63.18.
Follow the vendor remediation steps referenced by CTX696604 to perform the upgrade safely (including any pre-upgrade checks and rollback planning).
If you cannot patch immediately (temporary mitigation)
Disable or remove the relevant affected roles/features temporarily:
Stop using the NetScaler ADC as an Oracle load balancer, and/or
Disable DNS Proxy and/or DNS recursive resolver functions.
Route traffic for those functions to an alternative resolver/load balancing path until upgrades complete.
What to monitor after change
Service health of the ADC/Gateway (stability, crashes, restarts).
DNS behavior (resolution success/error rates) if you provide DNS services.
No KEV listing was provided, and the press articles in the provided material did not report exploitation in the wild; still, monitor vendor advisories and your own logs for service instability while you prepare the upgrade.
CISA due date
Not provided in the supplied findings.
Technical context
Severity is listed as critical (CVSS 9.8). The weakness is memory overflow (CWE-119), which can corrupt process memory and lead to unpredictable/erroneous behavior or Denial of Service. The attack vector is network-based with no authentication and no user interaction.
Impact conditions from the findings: exploitation risk is tied to how NetScaler ADC is deployed—specifically when configured as an Oracle load balancer, as a DNS Proxy, or as a DNS recursive resolver deployment.
Exploitation status: no KEV listing, no public exploit code on record, and no clear dated press claim of exploitation were provided in the findings. Therefore, treat this as urgent from an availability-risk standpoint, not because confirmed active exploitation was shown in the supplied sources.
Patching: vendor-fixed versions are available for netscaler application delivery controller (fixed in 72.61 / 63.18 / 37.272) and netscaler gateway (fixed in 72.61 / 63.18), with remediation guidance referenced as CTX696604.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.