CISA Orders Federal Agencies to Patch Actively Exploited Citrix NetScaler Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch Citrix NetScaler appliances affected by an actively exploited vulnerability by August 29.
Tracked as CVE-2026-8452, the high-severity security flaw is caused by a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers.
Citrix previously said the vulnerability could result in unexpected behavior or a denial-of-service condition. At the time, the company said exploitation was limited to denial-of-service attacks.
However, cybersecurity firm watchTowr reported in August that a successful exploit could allow attackers to achieve pre-authentication remote code execution as root on an unpatched NetScaler appliance.
“This is a memory overflow vulnerability that could cause unexpected behavior or denial of service, impacting NetScaler Gateway and AAA virtual servers,” Citrix said in its security advisory. “This vulnerability has not been observed to be exploited in its entirety.”
Internet threat-monitoring organization Shadowserver is currently tracking more than 22,000 NetScaler ADC appliances and approximately 1,800 NetScaler Gateway devices exposed to the internet.
Shadowserver’s figures do not indicate how many of these systems are honeypots, have vulnerable configurations, or have already been patched.

On Monday, CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities (KEV) Catalog. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch (FCEB) agencies must secure affected Citrix NetScaler appliances by August 29.
CISA has not disclosed technical details about the attacks exploiting CVE-2026-8452. The warning follows reports from security researchers and cybersecurity experts who flagged the vulnerability as actively exploited in “pray-and-spray” attacks.
Researchers have also reported that attackers may be using the vulnerability to deploy web shells on compromised NetScaler appliances. Citrix has not yet updated its CVE-2026-8452 security advisory to reflect the reported exploitation activity.
A week earlier, Citrix urged customers to immediately address two additional NetScaler vulnerabilities: CVE-2026-19490 and CVE-2026-19489. Remote, unauthenticated attackers could exploit these flaws to launch denial-of-service attacks or bypass authentication.
Although CVE-2026-19490 and CVE-2026-19489 have not been confirmed as exploited in the wild, Citrix previously warned about two other NetScaler vulnerabilities—CVE-2026-3055 and CVE-2026-4368—in March, shortly before threat actors began exploiting them.
Since November 2021, CISA has listed 23 Citrix vulnerabilities in its KEV Catalog. Seven of those vulnerabilities have been exploited by ransomware groups.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




