U.S. orders agencies to patch Citrix NetScaler flaw by Saturday
CISA ordered U.S. federal agencies to patch Citrix NetScaler ADC and Gateway appliances by August 29 against the CVE-2026-8452 remote code execution flaw.
Source: BleepingComputer · August 27, 2026 at 11:01 AM · AI-assisted report
Single-sourceWASHINGTON, 27 AUGUST 2026 —
CISA ordered U.S. federal agencies to patch Citrix NetScaler ADC and Gateway appliances by August 29 against the CVE-2026-8452 remote code execution flaw.
Market Impact
The high-severity vulnerability stems from a memory overflow weakness in NetScaler appliances configured with Gateway VPN or AAA virtual servers, according to Citrix’s June advisory.
Research from watchTowr in August showed threat actors can exploit the flaw to gain root-level remote code execution on unpatched appliances, not just denial-of-service attacks as Citrix initially warned.
CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities Catalog on Monday, triggering a 72-hour patching deadline under Binding Operational Directive 26-04.
The agency did not disclose active attack details, but security teams reported “pray and spray” campaigns deploying web shells on compromised NetScaler devices last week.
Shadowserver data shows 22,800 NetScaler ADC and 1,800 Gateway instances exposed online, though it is unclear how many remain vulnerable.
Citrix has not updated its advisory to confirm in-the-wild exploitation of CVE-2026-8452 and separately urged customers last week to patch two other NetScaler flaws—CVE-2026-19490 and CVE-2026-19489—that allow unauthenticated denial-of-service or authentication bypass.
Since November 2021, CISA has flagged 23 Citrix vulnerabilities as exploited in the wild, seven of which were later abused by ransomware groups.
The directive has no direct impact on Malaysian operators, but firms using Citrix NetScaler should treat it as a priority patch given the active exploitation risk.
Related: Citrix · CISA · WASHINGTON