CISA Orders Federal Agencies to Patch Exploited Citrix NetScaler Flaw by Saturday
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a high-severity Citrix NetScaler vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog and orders federal agencies to patch affected appliances by Saturday, August 29. The flaw, tracked as CVE-2026-8452, stems from a memory overflow weakness affecting NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA virtual servers. The directive applies to Federal Civilian Executive Branch agencies under Binding Operational Directive 26-04.
The vulnerability draws heightened urgency after security firm watchTowr demonstrates in August that attackers can achieve remote code execution as root on unpatched instances. Citrix initially says in June that the flaw only enables denial-of-service attacks and observes no unmitigated exploitation. CISA's warning follows reports from researchers of active "pray and spray" attacks deploying web shells on compromised appliances, though Citrix has yet to update its advisory to acknowledge in-the-wild exploitation.
Shadowserver currently tracks more than 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online, though it remains unclear how many are patched, misconfigured, or honeypots. Separately, Citrix urges customers to secure two additional NetScaler flaws, CVE-2026-19490 and CVE-2026-19489, which remote unauthenticated attackers can exploit for denial-of-service or authentication bypass. While those flaws are not yet tagged as exploited, organizations running NetScaler appliances are advised to prioritize patching all three vulnerabilities.