CVE Tools

CVE-2026-8655

Multiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of Service

No known exploitation. EPSS puts it in the 48th percentile. A vendor fix is available.

Published Updated Sources: CVE.org, NVD

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Check whether your deployment is NetScaler ADC or NetScaler Gateway, and confirm if it is configured as an Oracle load balancer, a DNS Proxy, or a DNS recursive resolver.
  2. Check your current NetScaler software version (Administration UI or system/version page).
  3. Upgrade to a fixed version: for ADC or Gateway, move to 72.61 (or 63.18 / 37.272 as applicable), and for the corresponding ADC/Gateway branches ensure your target line matches the vendor’s fixed versions.
  4. If you cannot upgrade right away, reduce exposure by disabling the affected roles/features that match your configuration (Oracle LB, DNS Proxy, or DNS recursive resolver) until patched.

What it is

From the CVE record

Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment

In plain language

Written by AI from the record

CVE-2026-8655 is a NetScaler ADC/Gateway bug that an outsider can trigger over the network to crash the service or make it behave unpredictably; you should update if you run NetScaler as an Oracle load balancer or DNS proxy/recursive resolver.

CVE-2026-8655 is a set of unauthenticated, network-triggerable memory overflow flaws (CWE-119) in netscaler application delivery controller and netscaler gateway; exploitation causes unpredictable/erroneous behavior or Denial of Service when NetScaler ADC is configured as an Oracle LB, DNS Proxy, or DNS recursive resolver.

If you're affected

  • Service outages for customer traffic
  • Unreliable DNS resolution
  • Gateway/LB instability
  • Potential disruption of business operations

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS48th
CISA KEV

Not in the catalog. CISA has not confirmed exploitation.

Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

0.6% chance of exploitation activity in the next 30 days, which ranks it in the 48th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

6 events over 15 days, from the signal feeds we watch.

  1. OpenVAS check added
  2. Patch availablerecord updated
  3. Publishedweakness classified, att&ck mapped

Affected products

Technical detail

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Scored 9.8 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity HighTotal loss of integrity — attacker can modify any data in the component
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for ADC, not every advisory.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store