CISA Warns Citrix NetScaler CVE-2026-8452 Is Under Active Attack

CISA has added a previously patched Citrix NetScaler ADC and Gateway flaw, CVE-2026-8452, to its Known Exploited Vulnerabilities catalog after attackers chained a watchTowr proof-of-concept into unauthenticated remote code execution and started dropping web shells.

CISA Warns Citrix NetScaler CVE-2026-8452 Is Under Active Attack

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, to its Known Exploited Vulnerabilities (KEV) catalog after threat intelligence firms reported active exploitation. Federal civilian agencies have until August 29, 2026 to patch or mitigate.

From memory bug to unauthenticated RCE

Citrix originally disclosed CVE-2026-8452 on June 30, 2026 as a memory overflow leading to unpredictable behaviour and denial of service, and shipped fixes the same day in NetScaler versions 14.1-72.61, 13.1-63.18 and 13.1-37.272. The flaw is only reachable when an appliance is configured as a Gateway - SSL VPN, ICA Proxy, CVPN or RDP Proxy - or as an AAA virtual server.

On August 14, researchers at watchTowr Labs published a technical writeup and working proof-of-concept showing the same bug could be chained into full, unauthenticated remote code execution - a materially worse outcome than Citrix's own advisory described.

Help Net Security cybersecurity coverage

Web shells in the wild within days

Days after the PoC dropped, threat intel firm Defused reported the first exploitation attempts on its EX sensors, and security company Previdian said on August 27 that attackers were dropping web shells named "x.php" and "z.php" and running discovery commands such as "id" and "echo" to map compromised NetScaler appliances, with hits from at least three unique IPs across three countries. Citrix's own advisory has not yet been updated to acknowledge in-the-wild exploitation.

Part of a larger KEV drop

CVE-2026-8452 was one of six flaws CISA added to KEV on August 26. The others include two older Red Hat issues (CVE-2015-3246 and CVE-2015-5287), a Microsoft SQL Server bug (CVE-2019-1068), an Ajax.NET Professional deserialization flaw (CVE-2021-23758) and a Linux Kernel vulnerability (CVE-2022-0995) - a pattern that mirrors the surge in edge-device exploitation seen against GitLab, Cisco Crosswork and Microsoft's Entra ID stack over the last two weeks.

What defenders should do

Administrators still on unpatched NetScaler builds should treat the appliance as potentially compromised, apply the June 30 fix or a newer release, rotate session tokens and TLS material, and hunt for the "x.php" and "z.php" artifacts and outbound traffic to unknown IPs. The rapid weaponization of PoC code is now the norm for edge devices, not the exception.

Reporting based on coverage from Help Net Security, watchTowr Labs, Previdian and CISA.

Category: Cyber Security

Tags: Cybersecurity CVE Patch Tuesday

Related Articles