Actively exploited Citrix NetScaler flaw puts 22,000+ appliances at risk
CISA confirms hackers are exploiting a Citrix NetScaler vulnerability, CVE-2026-8452, to plant web shells on unpatched systems. Researchers showed the bug allows full remote code execution as root, and federal agencies have until Saturday to patch.
A Citrix NetScaler vulnerability patched in June and originally described as a denial-of-service bug has been shown to allow full unauthenticated remote code execution as root. Security researchers published proof-of-concept code in August, and threat intelligence firms soon observed real attackers dropping web shells on unpatched appliances. CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 26 and ordered federal agencies to patch by August 29. Shadowserver tracks more than 22,000 exposed NetScaler ADC appliances and nearly 1,800 exposed Gateway instances online.