Citrix NetScaler Bug CVE-2026-8452 Exploited in the Wild

Citrix NetScaler Bug CVE-2026-8452 Exploited in the Wild

By Sofia Ramirez
Publication Date: 2026-08-27 07:10:00

CISA ordered federal agencies on August 26 to patch Citrix NetScaler flaw CVE-2026-8452, which the vendor disclosed on June 30 as a denial-of-service bug and which attackers are now exploiting for unauthenticated remote code execution.

What to Know?

  • Citrix rated CVE-2026-8452 a memory overflow leading to denial of service, scoring it 8.8 on the CVSS v4.0 scale.
  • WatchTowr published analysis and proof-of-concept code on August 14 showing the same flaw allows unauthenticated remote code execution.
  • Previdian saw attackers drop web shells named x.php and z.php, then run discovery commands including id and echo.
  • CISA added the flaw to its Known Exploited Vulnerabilities catalog and gave federal agencies until August 29 to remediate.
  • Only appliances configured as an AAA virtual server or a Gateway VPN server meet the vendor’s stated exploitation preconditions.

How It Happened?

Citrix’s advisory CTX696604 describes CVE-2026-8452 as a memory overflow that…