CISA: Patch Citrix NetScaler CVE-2026-8452; attacks reported

CISA ordered agencies to patch Citrix NetScaler flaw CVE-2026-8452 after a public proof-of-concept and reports of live attacks dropping web shells and running discovery commands.

The Cybersecurity and Infrastructure Security Agency urged federal agencies to immediately patch Citrix NetScaler vulnerability CVE-2026-8452 after a public proof-of-concept and reports of active exploitation. CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 26 and directed agencies to remediate by August 29.

Citrix released fixes on June 30. The vendor said the flaw affects NetScaler appliances configured as an AAA virtual server or a Gateway VPN server. Patches are included in versions 14.1-72.61 (FIPS), 13.1-63.18 and 13.1-37.272. Citrix described CVE-2026-8452 as a high-severity memory overflow that can lead to unpredictable behavior or denial of service.

Security firm WatchTowr published an analysis and proof-of-concept on August 14 that showed a path to unauthenticated remote code execution. Two security teams observed exploitation in the wild shortly after the PoC appeared. Observers reported attackers dropped a web shell and ran basic discovery commands such as “id” and “echo” on compromised appliances.

CISA’s listing of CVE-2026-8452 in the KEV catalog indicates confirmed exploitation and sets a remediation deadline for agencies. Citrix has not updated its advisory to explicitly confirm the public reports of in-the-wild attacks.

A separate NetScaler vulnerability, CVE-2026-8451, was seen under attack within 24 hours of disclosure earlier this year. Network administrators and security teams are advised to check device roles, confirm software versions, and install the Citrix fixes for the builds named by the vendor.

Articles by this author