CISA says attackers are exploiting Citrix NetScaler flaw CVE-2026-8452 and urges immediate patching

Attackers are exploiting a recently patched Citrix NetScaler vulnerability, putting organizations that use affected VPN and access gateway appliances at risk. CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog on August 26 and ordered federal agencies to remediate by August 29. Citrix had described the bug as a high-severity memory overflow affecting appliances configured as AAA virtual servers or Gateway VPN servers, but public analysis and proof-of-concept code showed unauthenticated remote code execution and web-shell deployment. Fixed versions include 14.1-72.61 (FIPS), 13.1-63.18, and 13.1-37.272.
Why it matters: Organizations using Citrix NetScaler for remote access may be exposed to internet-based compromise, not just service crashes, so this is a patch-now issue. Defenders should identify exposed AAA and Gateway VPN deployments, update immediately, and check for web shells or reconnaissance commands on affected appliances.

Sources

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
Sergiu Gatlan 2026.08.27 97% relevant
This directly updates the same event by adding that CISA has now ordered U.S. federal agencies to patch CVE-2026-8452 by August 29 under BOD 26-04, and reiterates that recent attacks have included web-shell deployment after researchers showed the bug could lead to root remote code execution.
Recent Citrix NetScaler Vulnerability Exploited in the Wild
Eduard Kovacs 2026.08.27 100% relevant
This article establishes a distinct tracked event centered on CVE-2026-8452: active exploitation, KEV addition, public PoC timing, and specific affected NetScaler configurations and fixed versions.
← Back to all stories