Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)
Reported exploitedCitrix NetScaler ADCCitrix NetScaler GatewayOur summary
CISA has designated CVE-2026-8452 as actively exploited, adding it to its Known Exploited Vulnerabilities catalog following the public release of a proof-of-concept exploit by watchTowr Labs. This vulnerability affects Citrix NetScaler ADC and Gateway appliances configured with specific virtual servers, where a memory overflow can lead to denial of service or potentially unauthenticated remote code execution. While Citrix issued patches on June 30, 2026, attackers began leveraging the flaw shortly after the technical details were shared, deploying web shells for initial access.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.