CVE Tools

Recent Citrix NetScaler Vulnerability Exploited in the Wild

SecurityWeekBy Eduard Kovacs

Reported exploitedCitrix NetScaler

Our summary

CISA has directed US government organizations to urgently remediate CVE-2026-8452, a high-severity flaw in Citrix NetScaler that is currently being actively attacked. Although initially described by the vendor as a potential denial-of-service issue, security researchers have confirmed that the vulnerability allows for unauthenticated remote code execution on devices configured as AAA virtual servers or Gateway VPN servers.

Active exploitation involves attackers deploying web shells and running reconnaissance commands, prompting CISA to add the bug to its Known Exploited Vulnerabilities catalog with an August 29 deadline. To mitigate the risk, administrators must update their appliances to fixed versions 14.1-72.61 (FIPS), 13.1-63.18, or 13.1-37.272.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store