The US Cybersecurity and Infrastructure Security Agency added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog on Monday.
The order requires Federal Civilian Executive Branch agencies to secure affected Citrix NetScaler appliances by Saturday, August 29. The deadline follows CISA’s Binding Operational Directive 26-04.
CVE-2026-8452 is a high-severity memory overflow vulnerability. It affects NetScaler ADC and NetScaler Gateway appliances that use Gateway VPN or AAA virtual servers.
Researchers demonstrated root-level access
Citrix initially said the flaw could cause unpredictable behaviour or denial-of-service attacks. However, security firm watchTowr later demonstrated that attackers could use the issue to gain remote code execution as root on unpatched devices.
That finding significantly raised the risk linked to the Citrix NetScaler RCE vulnerability. Root-level access could allow attackers to take full control of an affected appliance.
Researchers and security experts also reported active exploitation during the past week. The attacks reportedly use broad scanning campaigns to deploy web shells on compromised systems.
Thousands of appliances remain exposed
Shadowserver tracks more than 22,000 NetScaler ADC appliances and almost 1,800 NetScaler Gateway instances exposed online.
However, the available data does not show how many systems use vulnerable configurations, have already received patches or are honeypots.
Citrix has not yet updated its security advisory to confirm that attackers are exploiting CVE-2026-8452 in the wild.
Citrix faces continued NetScaler security pressure
Citrix recently warned customers to patch two further NetScaler vulnerabilities, CVE-2026-19490 and CVE-2026-19489. Attackers could potentially use those flaws for denial-of-service attacks or authentication bypasses.
Earlier this year, Citrix also urged administrators to patch CVE-2026-3055 and CVE-2026-4368. Threat actors began abusing those vulnerabilities only days later.
Since November 2021, CISA has listed 23 Citrix vulnerabilities as actively exploited. Ransomware groups have abused seven of those flaws.


0 responses to “Citrix NetScaler RCE flaw added to KEV catalog”