CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
Reported exploitedNetScaler ADCNetScaler GatewayOur summary
CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog, directing federal agencies to patch affected Citrix NetScaler ADC and NetScaler Gateway appliances by Saturday. Although initially disclosed in June as a memory overflow risk limited to denial-of-service impacts, recent research confirms that threat actors are using the bug to achieve remote code execution as root. With over 22,000 exposed appliances identified online, the directive under BOD 26-04 highlights the critical need for immediate remediation against these active attacks.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.