Skip to content
Tech News
← Back to articles

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

read original more articles
Why This Matters

The urgent directive from CISA highlights the critical need for government agencies to patch a severe Citrix NetScaler vulnerability actively exploited by cybercriminals. This underscores the importance of timely vulnerability management to protect sensitive infrastructure from remote code execution attacks. For consumers and organizations alike, it emphasizes the ongoing threat landscape and the necessity of proactive cybersecurity measures.

Key Takeaways

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch their Citrix NetScaler appliances against an actively exploited vulnerability by Saturday.

Tracked as CVE-2026-8452, this high-severity security flaw stems from a memory overflow weakness affecting NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers.

While Citrix said in June that threat actors could only exploit the flaw in denial-of-service (DoS) attacks, cybersecurity firm watchTowr showed in August that successful exploitation can also allow attackers to gain remote code execution as root on unpatched NetScaler instances.

"This is a memory overflow vulnerability that may lead to unpredictable behavior or denial of service and impacts NetScaler Gateway or AAA virtual server," Citrix said at the time. "We have not observed any unmitigated exploitation of this vulnerability as well."

At the moment, Internet threat watchdog Shadowserver tracks over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online.

However, there is no information on how many are honeypots, have vulnerable configurations, or have already been patched.

Citrix NetScaler appliances exposed online (Shadowserver)

​​On Monday, CISA added the CVE-2026-8452 flaw to its Known Exploited Vulnerabilities (KEV) Catalog, ordering Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by August 29, as mandated by Binding Operational Directive (BOD) 26-04.

CISA didn't share any details on the attacks currently targeting the CVE-2026-8452 flaw, but its warning comes one week after security researchers and cybersecurity experts flagged the vulnerability as actively exploited in "pray and spray" attacks that deploy web shells on compromised appliances.

Citrix has yet to update the security advisory for the CVE-2026-8452 vulnerability to acknowledge that it's now being targeted in the wild.

... continue reading