Attackers are exploiting a recently patched Citrix NetScaler vulnerability, putting organizations that use affected VPN and access gateway appliances at risk. CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog on August 26 and ordered federal agencies to remediate by August 29. Citrix had described the bug as a high-severity memory overflow affecting appliances configured as AAA virtual servers or Gateway VPN servers, but public analysis and proof-of-concept code showed unauthenticated remote code execution and web-shell deployment. Fixed versions include 14.1-72.61 (FIPS), 13.1-63.18, and 13.1-37.272.
Why it matters: Organizations using Citrix NetScaler for remote access may be exposed to internet-based compromise, not just service crashes, so this is a patch-now issue. Defenders should identify exposed AAA and Gateway VPN deployments, update immediately, and check for web shells or reconnaissance commands on affected appliances.
Sergiu Gatlan
2026.08.27
97% relevant
This directly updates the same event by adding that CISA has now ordered U.S. federal agencies to patch CVE-2026-8452 by August 29 under BOD 26-04, and reiterates that recent attacks have included web-shell deployment after researchers showed the bug could lead to root remote code execution.
Eduard Kovacs
2026.08.27
100% relevant
This article establishes a distinct tracked event centered on CVE-2026-8452: active exploitation, KEV addition, public PoC timing, and specific affected NetScaler configurations and fixed versions.
← Back to all stories