Citrix NetScaler flaw exploited following POC release

Citrix NetScaler flaw exploited following POC release

By fieldeffectsoft
Publication Date: 2026-08-20 13:03:00

At a glance:

  • Open-source reporting indicates CVE-2026-8452 is being exploited in the wild following the release of public proof-of-concept exploit code.

  • The vulnerability affects Citrix NetScaler ADC and NetScaler Gateway deployments configured as a Gateway or Authentication, Authorization, and Accounting (AAA) virtual server and was patched on June 30, 2026.

  • Citrix describes the issue as a memory overflow vulnerability, while watchTowr researchers demonstrated a path to pre-authentication remote code execution on vulnerable systems.

Threat summary

On August 17, 2026, the Canadian Centre for Cyber Security reported indications that a recently patched vulnerability affecting Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway is being exploited in the wild. The report followed the publication of a technical analysis and proof-of-concept (PoC) exploit by watchTowr Labs a few days earlier.

Citrix NetScaler ADC and NetScaler Gateway are widely used to…