The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch their Citrix NetScaler appliances against an actively exploited vulnerability by Saturday.
Tracked as CVE-2026-8452, this high-severity security flaw stems from a memory overflow weakness affecting NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers.
While Citrix said in June that threat actors could only exploit the flaw in denial-of-service (DoS) attacks, cybersecurity firm watchTowr showed in August that successful exploitation can also allow attackers to gain remote code execution as root on unpatched NetScaler instances.
“This is a memory overflow vulnerability that may lead to unpredictable behavior or denial of service and impacts NetScaler Gateway or AAA virtual server,” Citrix said at the time. “We have not observed any unmitigated exploitation of this vulnerability as well.”
At the moment, Internet threat watchdog Shadowserver tracks over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online.
However, there is no information on how many are honeypots, have vulnerable configurations, or have already been patched.
On Monday, CISA added the CVE-2026-8452 flaw to its Known Exploited Vulnerabilities (KEV) Catalog, ordering Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by August 29, as mandated by Binding Operational Directive (BOD) 26-04.
CISA didn’t share any details on the attacks currently targeting the CVE-2026-8452 flaw, but its warning comes one week after security researchers and cybersecurity experts flagged the vulnerability as actively exploited in “pray and spray” attacks that deploy web shells on compromised appliances.
Citrix has yet to update the security advisory for the CVE-2026-8452 vulnerability to acknowledge that it’s now being targeted in the wild.
One week ago, the company also urged customers to immediately secure their systems against two other NetScaler vulnerabilities, tracked as CVE-2026-19490 and CVE-2026-19489, that remote, unauthenticated threat actors can exploit in DoS attacks or to bypass authentication.
While these two flaws have not been tagged as exploited in the wild, Citrix asked admins to patch two other NetScaler vulnerabilities (CVE-2026-3055 and CVE-2026-4368) in March, days before threat actors began abusing them.
Since November 2021, the U.S. cybersecurity agency has flagged 23 Citrix vulnerabilities as exploited in the wild, seven of them also abused by ransomware gangs.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
CISA orders urgent patching of actively exploited Zimbra flaw
Critical RCE flaw in Windows IKE Extension now actively exploited
Citrix urges admins to patch new NetScaler flaws as soon as possible
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
Ubiquiti patches three max severity security vulnerabilities
Police arrests dozens of suspects in global cybercrime crackdown
Microsoft Teams now lets admins block external bots from meetings
See how AI is reshaping email attacks. Download the 2026 Kaseya Email Security Report.
Discover why encryption and key management are critical for modern business.
Protect yourself from data brokers, scammers, and the next data breach with digital identities.
Overdue a password health-check? Audit your Active Directory for free
Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.
Discover how least agency keeps your AI tools capable, controlled, and secure.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.


