LIVE · cybersecurity feed
Live wire
CISA orders feds to patch Citrix NetScaler RCE flaw by SaturdayUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure AttacksCritical Avada WordPress theme flaw enables zero-click RCECVE-2026-15409 · Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodesCVE-2026-60004 · Hackers now exploit critical Gitea flaw in code injection attacksEmployee benefits platform Paylogix says hackers stole financial and health dataU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesCVE-2026-61979 · Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableCVE-2024-28224 · A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
vulnerabilityhigh

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

CISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. [...]

zeroday.news ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies apply patches for a critical vulnerability, CVE-2026-8452, affecting Citrix NetScaler appliances by Saturday, August 29. This directive, issued under Binding Operational Directive (BOD) 26-04, follows the addition of CVE-2026-8452 to CISA's Known Exploited Vulnerabilities (KEV) Catalog.

The flaw, initially described by Citrix in June as a high-severity memory overflow that could lead to denial-of-service (DoS) or unpredictable behavior, impacts NetScaler ADC and NetScaler Gateway appliances. Specifically, it affects configurations utilizing Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers. At that time, Citrix stated they had not observed any unmitigated exploitation of this vulnerability.

However, cybersecurity firm watchTowr demonstrated in August that successful exploitation of CVE-2026-8452 could enable attackers to achieve remote code execution as root on unpatched NetScaler instances, a more severe outcome than initially indicated by Citrix.

CISA's warning comes approximately one week after security researchers and experts began reporting active exploitation of this vulnerability. These attacks are described as "pray and spray" campaigns, where attackers deploy web shells on compromised appliances. CISA has not released specific details regarding the attacks currently targeting the flaw.

Despite the confirmed active exploitation, Citrix has not yet updated its official security advisory for CVE-2026-8452 to acknowledge that it is being targeted in the wild.

Internet threat watchdog Shadowserver currently tracks over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online. It is unclear how many of these have vulnerable configurations, are honeypots, or have already been patched.

This is not the first time CISA has issued urgent warnings regarding Citrix vulnerabilities. Since November 2021, the agency has flagged 23 Citrix flaws as actively exploited, with seven of these also being abused by ransomware groups. Just last week, Citrix also urged customers to patch two other NetScaler vulnerabilities, CVE-2026-19490 and CVE-2026-19489, which could allow remote, unauthenticated attackers to perform DoS attacks or bypass authentication. While these two have not yet been tagged as exploited, Citrix had previously advised patching CVE-2026-3055 and CVE-2026-4368 in March, shortly before those flaws saw active abuse.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Critical Avada WordPress theme flaw enables zero-click RCE

A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. [...]

breach

OpenAI: Hugging Face Incident a “Warning Shot” to the World

OpenAI reveals that unauthorized message boards were at the heart of the recent Hugging Face breach

securitycritical

US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

The operation focused on a group named QTFY, which offers hacking services to the Chinese government and others. The post US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks appeared first on SecurityWeek.

nation-state

Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure

The order says any foreign-produced equipment deemed to pose national security risks can’t be purchased or installed. The post Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure appeared first on CyberScoop.

malware

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

GoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.

security

More than 100 water systems were hit in July cyberattacks

'These are test runs for a larger-scale attack'