The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies apply patches for a critical vulnerability, CVE-2026-8452, affecting Citrix NetScaler appliances by Saturday, August 29. This directive, issued under Binding Operational Directive (BOD) 26-04, follows the addition of CVE-2026-8452 to CISA's Known Exploited Vulnerabilities (KEV) Catalog.
The flaw, initially described by Citrix in June as a high-severity memory overflow that could lead to denial-of-service (DoS) or unpredictable behavior, impacts NetScaler ADC and NetScaler Gateway appliances. Specifically, it affects configurations utilizing Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers. At that time, Citrix stated they had not observed any unmitigated exploitation of this vulnerability.
However, cybersecurity firm watchTowr demonstrated in August that successful exploitation of CVE-2026-8452 could enable attackers to achieve remote code execution as root on unpatched NetScaler instances, a more severe outcome than initially indicated by Citrix.
CISA's warning comes approximately one week after security researchers and experts began reporting active exploitation of this vulnerability. These attacks are described as "pray and spray" campaigns, where attackers deploy web shells on compromised appliances. CISA has not released specific details regarding the attacks currently targeting the flaw.
Despite the confirmed active exploitation, Citrix has not yet updated its official security advisory for CVE-2026-8452 to acknowledge that it is being targeted in the wild.
Internet threat watchdog Shadowserver currently tracks over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online. It is unclear how many of these have vulnerable configurations, are honeypots, or have already been patched.
This is not the first time CISA has issued urgent warnings regarding Citrix vulnerabilities. Since November 2021, the agency has flagged 23 Citrix flaws as actively exploited, with seven of these also being abused by ransomware groups. Just last week, Citrix also urged customers to patch two other NetScaler vulnerabilities, CVE-2026-19490 and CVE-2026-19489, which could allow remote, unauthenticated attackers to perform DoS attacks or bypass authentication. While these two have not yet been tagged as exploited, Citrix had previously advised patching CVE-2026-3055 and CVE-2026-4368 in March, shortly before those flaws saw active abuse.






