Recent Citrix NetScaler Vulnerability Exploited in the Wild

Recent Citrix NetScaler Vulnerability Exploited in the Wild
CISA is urging government organizations to urgently patch a newly exploited Citrix NetScaler flaw, CVE-2026-8452, which Citrix fixed on June 30 and which WatchTowr showed could enable unauthenticated remote code execution. Security researchers and threat intelligence firms observed attackers deploying web shells and running discovery commands soon after the exploit details and PoC were published. #CVE-2026-8452 #Citrix #NetScaler #WatchTowr #CISA

Keypoints

  • CISA added CVE-2026-8452 to its KEV catalog and ordered agencies to patch it by August 29.
  • The flaw affects Citrix NetScaler appliances configured as an AAA virtual server or Gateway VPN server.
  • Citrix says the issue can cause unpredictable behavior and denial of service.
  • WatchTowr demonstrated unauthenticated remote code execution and released PoC code on August 14.
  • Researchers observed in-the-wild exploitation involving web shells and basic discovery commands.

Read More: https://www.securityweek.com/recent-citrix-netscaler-vulnerability-exploited-in-the-wild/