BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Aug 27, 2026 · 2 min read · Original story

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch their Citrix NetScaler appliances against an actively exploited vulnerability by Saturday.

Tracked as CVE-2026-8452, this high-severity security flaw stems from a memory overflow weakness affecting NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers.

While Citrix said in June that threat actors could only exploit the flaw in denial-of-service (DoS) attacks, cybersecurity firm watchTowr showed in August that successful exploitation can also allow attackers to gain remote code execution as root on unpatched NetScaler instances.

"This is a memory overflow vulnerability that may lead to unpredictable behavior or denial of service and impacts NetScaler Gateway or AAA virtual server," Citrix said at the time. "We have not observed any unmitigated exploitation of this vulnerability as well."

At the moment, Internet threat watchdog Shadowserver tracks over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online.

However, there is no information on how many are honeypots, have vulnerable configurations, or have already been patched.

Citrix NetScaler appliances exposed online (Shadowserver)

​​On Monday, CISA added the CVE-2026-8452 flaw to its Known Exploited Vulnerabilities (KEV) Catalog, ordering Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by August 29, as mandated by Binding Operational Directive (BOD) 26-04.

CISA didn't share any details on the attacks currently targeting the CVE-2026-8452 flaw, but its warning comes one week after security researchers and cybersecurity experts flagged the vulnerability as actively exploited in "pray and spray" attacks that deploy web shells on compromised appliances.

Citrix has yet to update the security advisory for the CVE-2026-8452 vulnerability to acknowledge that it's now being targeted in the wild.

One week ago, the company also urged customers to immediately secure their systems against two other NetScaler vulnerabilities, tracked as CVE-2026-19490 and CVE-2026-19489, that remote, unauthenticated threat actors can exploit in DoS attacks or to bypass authentication.

While these two flaws have not been tagged as exploited in the wild, Citrix asked admins to patch two other NetScaler vulnerabilities (CVE-2026-3055 and CVE-2026-4368) in March, days before threat actors began abusing them.

Since November 2021, the U.S. cybersecurity agency has flagged 23 Citrix vulnerabilities as exploited in the wild, seven of them also abused by ransomware gangs.

References in this story

  1. NVD - Home nvd.nist.gov
  2. NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816… support.citrix.com NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474
  3. You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) labs.watchtowr.com Suddenly, you’re in a room. You look around - oh, you’re surrounded by other new starters at your new job. Yes, it’s Monday, and you’re being onboarded. You know the drill - it’s the typical enterprise “please don’t be…
  4. AI Threat Readiness Playbook for Cloud Security Teams | Wiz wiz.io Prepare for AI-driven threats. Discover best practices for exposure management, AI-powered code analysis, and real-time threat detection.
  5. Time series · IoT device statistics · The Shadowserver Foundation dashboard.shadowserver.org
  6. Time series · IoT device statistics · The Shadowserver Foundation dashboard.shadowserver.org
  7. CISA Adds Six Known Exploited Vulnerabilities to Catalog | CISA www.cisa.gov
  8. Known Exploited Vulnerabilities Catalog | CISA www.cisa.gov For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of…
  9. Ryan Dewhurst (@ethicalhack3r) on X x.com This morning we started seeing exploitation for CVE-2026-8452 (Citrix Netscaler PreAuthRCE). The attackers were dropping a web shell named "x.php" and "z.php", and running discovery commands, like "id" and "echo". So…
  10. Defused (@DefusedCyber) on X x.com 🚨 Exploit activity continues high over the weekend, with new recon activity on the horizon 1. A FortiSandbox endpoint (a VM-provisioning / VNC-start route that appears in none of the 2026 FortiSandbox advisories) saw…
  11. Kevin Beaumont (@[email protected]) cyberplace.social CVE-2026-8452 in Netscaler is under active pray and spray exploitation - somebody popped my honeypot with it today. Three webshells, x.php, y.php and z.php I don't think this one will be super impactful in terms of…
  12. NVD - CVE-2026-19490 nvd.nist.gov
  13. NVD - CVE-2026-19489 nvd.nist.gov
  14. Citrix urges admins to patch NetScaler flaws as soon as possible www.bleepingcomputer.com Citrix has patched two NetScaler ADC and NetScaler Gateway vulnerabilities, one of which is very similar to the CitrixBleed and CitrixBleed2 flaws exploited in zero-day attacks in recent years.
  15. NVD - CVE-2026-3055 nvd.nist.gov
  16. NVD - CVE-2026-4368 nvd.nist.gov
  17. Critical Citrix NetScaler memory flaw actively exploited in attacks www.bleepingcomputer.com Hackers are exploiting a critical severity vulnerability, tracked as CVE-2026-3055, in Citrix NetScaler ADC and NetScaler Gateway appliances to obtain sensitive data.
  18. Known Exploited Vulnerabilities Catalog | CISA www.cisa.gov For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of…

Guides related to this story

← Back to all news