The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch Citrix NetScaler appliances against an actively exploited vulnerability by Saturday. The order applies to Federal Civilian Executive Branch (FCEB) agencies, which must secure all vulnerable Citrix systems by August 29, as required under Binding Operational Directive 26-04. CISA added the flaw, tracked as CVE-2026-8452, to its Known Exploited Vulnerabilities (KEV) Catalog on Monday.
The high-severity flaw is a memory overflow weakness affecting NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers. Citrix initially said in June that threat actors could only exploit the flaw for denial-of-service (DoS) attacks. However, cybersecurity firm watchTowr demonstrated in August that successful exploitation can also allow attackers to gain remote code execution as root on unpatched NetScaler instances.
Internet threat watchdog Shadowserver currently tracks over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online. There is no information on how many of those are honeypots, have vulnerable configurations, or have already been patched. CISA did not share details on the attacks targeting the flaw, but its warning comes one week after security researchers flagged the vulnerability as actively exploited in "pray and spray" attacks that deploy web shells on compromised appliances.
Citrix has not yet updated its security advisory for CVE-2026-8452 to acknowledge that it is now being targeted in the wild. One week ago, the company urged customers to immediately secure their systems against two other NetScaler vulnerabilities, tracked as CVE-2026-19490 and CVE-2026-19489. Remote, unauthenticated threat actors can exploit those two flaws in DoS attacks or to bypass authentication, though they have not been tagged as exploited in the wild.
In March, Citrix asked admins to patch two other NetScaler vulnerabilities, CVE-2026-3055 and CVE-2026-4368, days before threat actors began abusing them. Since November 2021, CISA has flagged 23 Citrix vulnerabilities as exploited in the wild, seven of which have also been abused by ransomware gangs. The agency has also recently warned of hackers exploiting flaws in Langflow, N-central, and Apache Tomcat.
More cybersecurity news from TechManNews.








