CISA Orders Emergency Patching for Actively Exploited Citrix NetScaler Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for federal agencies to patch **Citrix NetScaler** appliances against a high-severity, actively exploited memory overflow vulnerability, **CVE-2026-8452**. Initially downplayed as a potential Denial-of-Service (DoS) threat, recent findings confirm it can lead to remote code execution (RCE) as root, putting critical infrastructure at significant risk.
The **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** has mandated that government agencies immediately patch their **Citrix NetScaler** appliances by Saturday, August 29, against an actively exploited vulnerability.

Tracked as **CVE-2026-8452**, this high-severity security flaw originates from a memory overflow weakness impacting **NetScaler ADC** and **NetScaler Gateway** appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers.
While **Citrix** initially stated in June that threat actors could only exploit the flaw in denial-of-service (DoS) attacks, cybersecurity firm **watchTowr** demonstrated in August that successful exploitation can also allow attackers to gain remote code execution as root on unpatched **NetScaler** instances.
**Citrix** had previously noted: "This is a memory overflow vulnerability that may lead to unpredictable behavior or denial of service and impacts **NetScaler Gateway** or AAA virtual server. We have not observed any unmitigated exploitation of this vulnerability as well."
Currently, the Internet threat watchdog **Shadowserver** tracks over 22,000 **NetScaler ADC** appliances and nearly 1,800 **Gateway** instances exposed online. However, it remains unclear how many of these are honeypots, have vulnerable configurations, or have already been patched.

On Monday, **CISA** added **CVE-2026-8452** to its **Known Exploited Vulnerabilities (KEV) Catalog**, directing Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable **Citrix** appliances by August 29, as stipulated by **Binding Operational Directive (BOD) 26-04**.
**CISA** did not disclose specific details regarding the attacks exploiting **CVE-2026-8452**. However, this warning follows reports from security researchers and cybersecurity experts who observed the vulnerability being targeted in "pray and spray" attacks, which aim to deploy web shells on compromised appliances.
**Citrix** has yet to update its security advisory for **CVE-2026-8452** to acknowledge its active exploitation in the wild.
Just last week, the company also urged customers to immediately secure their systems against two other **NetScaler** vulnerabilities, **CVE-2026-19490** and **CVE-2026-19489**. These flaws allow remote, unauthenticated threat actors to perform DoS attacks or bypass authentication.
While **CVE-2026-19490** and **CVE-2026-19489** have not yet been flagged as exploited, **Citrix** previously advised administrators to patch two other **NetScaler** vulnerabilities (**CVE-2026-3055** and **CVE-2026-4368**) in March, days before threat actors began actively abusing them.
Since November 2021, **CISA** has identified 23 **Citrix** vulnerabilities as exploited in the wild, with seven of these also being leveraged by ransomware gangs.