• News/
  • bleepingcomputer-20260827091650

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

BleepingComputer
·
Sergiu Gatlan
·
Published Aug 27, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch their Citrix NetScaler appliances against an actively exploited vulnerability by Saturday. Tracked as CVE-2026-8452, this high-severity security flaw stems from a memory overflow weakness affecting NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers. While Citrix said in June that threat actors could only exploit the flaw in denial-of-service (DoS) attacks, cybersecurity firm watchTowr showed in August that successful exploitation can also allow attackers to gain remote code execution as root on unpatched NetScaler instances. "This is a memory overflow vulnerability that may lead to unpredictable behavior or denial of service and impacts NetScaler Gateway or AAA virtual server," Citrix said at the time. "We have not observed any unmitigated exploitation of this vulnerability as well." At the moment, Internet threat watchdog Shadowserver tracks over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online. However, there is no information on how many are honeypots, have vulnerable configurations, or have already been patched. ​​On Monday, CISA added the CVE-2026-8452 flaw to its Known Exploited Vulnerabilities (KEV) Catalog, ordering Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by August 29, as mandated by Bin...

Read full article

Affected Software

2 affected components
Citrix NetScaler ADC
Citrix NetScaler Gateway

Frequently Asked Questions

1

Which NetScaler deployments are affected by CVE-2026-8452?

The flaw affects NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA virtual servers. It is a high-severity memory overflow vulnerability.

2

What impact can exploitation have?

Citrix initially said the flaw could be used for denial-of-service attacks and cause unpredictable behavior. watchTowr later showed that successful exploitation can also provide remote code execution as root on unpatched NetScaler instances.

3

What action has CISA required from government agencies?

CISA ordered government agencies to patch affected Citrix NetScaler appliances by Saturday. The vulnerability is actively exploited and KEV-listed.

4

How large is the potentially exposed internet-facing footprint?

Shadowserver tracks more than 22,000 NetScaler ADC appliances and nearly 1,800 NetScaler Gateway instances exposed online. The article does not say how many are vulnerable, patched, or honeypots.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203