CVE•Published 2026-06-30•Modified 2026-07-01•1 article on news•6 live references•NVD data
CVE-2026-8655Citrix · Netscaler_application_delivery_controller
Vulnerability data via NVD (ingested)
CVSS v3.1
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS percentile
—
Description
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
Timeline
Published 2026-06-30
Modified 2026-07-01
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag1,440 hosts
vuln:CVE-2026-8655Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product
product:"Citrix Netscaler Application Delivery Controller"All exposed Citrix Netscaler Application Delivery Controller instances — cross-reference with the CVE's affected-version range.
Shodan · banner/body mention
http.html:"Netscaler Application Delivery Controller"HTTP body or banner mentions "Netscaler Application Delivery Controller" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-8655Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-8655Censys host search filtered to this CVE id.
grep.app
CVE-2026-8655Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-8655GitHub code search for direct mentions.
Google dork
"CVE-2026-8655" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (8)
CVE-2026-86558 repos
xairy/linux-kernel-exploitationunknown
A collection of links related to Linux kernel security and exploitation
Metarget/metargetPython
Metarget is a framework providing automatic constructions of vulnerable infrastructures.
bsauce/kernel-exploit-factoryC
Linux kernel CVE exploit analysis report and relative debug environment. You don't need to compile Linux kernel and configure your environment anymore.
Ostorlab/KEVunknown
Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.
SyntaxMethod/CVE-2026-42978-PoC-Researchunknown
CVE-2026-42978 Windows Push Notifications (WpnService) Use-After-Free & Race Condition PoC research, diagnostic scanner, and security audit module for AI Security Tool.
grizzzer/CVE-2026-42978-PoC-ResearchC
CVE-2026-42978 — Use-After-Free race condition in Windows Push Notifications (WpnService). Patch diff, root cause analysis, TOCTOU lab, Sysmon/ETW detection rules.
rxerium/CISA-KEVPython
An automated repo to track Nuclei template scanning capabilities against the CISA KEV.
loanvui/CVE-2026-62737PowerShell
CVE-2026-62737 ExecutionContext.sys arbitrary kernel-call PoC