CISA has ordered federal agencies to urgently patch Citrix NetScaler appliances against CVE-2026-8452, a high-severity memory overflow flaw that is being actively exploited and can enable remote code execution as root. The warning follows reports of “pray and spray” attacks deploying web shells, while Shadowserver shows tens of thousands of NetScaler devices exposed online. #CVE-2026-8452 #Citrix #NetScaler #CISA #Shadowserver
Keypoints
- CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities Catalog.
- Federal civilian agencies must patch vulnerable Citrix systems by August 29.
- The flaw affects NetScaler ADC and NetScaler Gateway with Gateway VPN or AAA virtual servers.
- watchTowr showed the bug can lead to remote code execution as root.
- Researchers say the flaw is being used in active attacks that deploy web shells.