AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 31 Aug, 08:10

Citrix NetScaler flaw CVE-2026-8452 escalates from a 'DoS-only' bug to full unauthenticated remote code execution, now under active exploitation

A Citrix NetScaler vulnerability patched in June as a low-severity denial-of-service issue turned out to allow full unauthenticated remote code execution. CISA has ordered federal agencies to patch by August 29 after active exploitation was observed. Per BleepingComputer and Help Net Security.

Citrix disclosed CVE-2026-8452 on June 30, 2026, describing it only as a memory overflow bug causing denial of service on NetScaler ADC and Gateway appliances configured with Gateway VPN or AAA virtual servers; a patch shipped the same day. On August 14, watchTowr Labs published a technical writeup and proof-of-concept showing the same flaw can be chained into full, unauthenticated remote code execution as root. Threat intelligence firms Defused and Previdian soon confirmed real-world exploitation, with Previdian reporting attackers dropping web shells named 'x.php' and 'z.php' and running discovery commands from three unique IP addresses in three different countries. Monitoring firm Shadowserver counts over 22,000 NetScaler ADC and nearly 1,800 Gateway instances still exposed online, though it is unclear how many are already patched. CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 26 and ordered federal agencies to patch by August 29 under Binding Operational Directive 26-04. Citrix's own advisory had not been updated to confirm in-the-wild exploitation as of the reporting date. Sources: BleepingComputer, Help Net Security.

#cyber
Published on