CVE Tools

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

BleepingComputerBy Sergiu Gatlan

Reported exploitedNetScaler ADCNetScaler Gateway

Our summary

CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog, directing federal agencies to patch affected Citrix NetScaler ADC and NetScaler Gateway appliances by Saturday. Although initially disclosed in June as a memory overflow risk limited to denial-of-service impacts, recent research confirms that threat actors are using the bug to achieve remote code execution as root. With over 22,000 exposed appliances identified online, the directive under BOD 26-04 highlights the critical need for immediate remediation against these active attacks.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store