CISA orders U.S. federal agencies to patch an actively exploited Citrix NetScaler vulnerability by August 29
CISA added CVE-2026-8452, an actively exploited Citrix NetScaler flaw, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch it by August 29, per BleepingComputer and SecurityWeek.
CISA added CVE-2026-8452, a Citrix NetScaler ADC and Gateway vulnerability, to its Known Exploited Vulnerabilities catalog on August 26 and ordered U.S. federal civilian agencies to secure all vulnerable appliances by August 29 under Binding Operational Directive 26-04. Citrix patched the flaw in June, describing it only as a denial-of-service risk, but cybersecurity firm WatchTowr published proof-of-concept code on August 14 showing it also enables unauthenticated remote code execution as root. Researchers reported in-the-wild exploitation shortly after, with attackers dropping web shells and running discovery commands on unpatched appliances. Shadowserver counts more than 22,000 exposed NetScaler ADC appliances and nearly 1,800 exposed Gateway instances online, though it is unclear how many remain unpatched. Sources: BleepingComputer, SecurityWeek.