The U.S. Cybersecurity and Infrastructure Security Agency has ordered government agencies to patch their Citrix NetScaler appliances against a vulnerability that is already being exploited, with a deadline of Saturday.
The CVE-2026-8452 Memory Overflow Flaw
The high-severity flaw, tracked as CVE-2026-8452, stems from a memory overflow weakness affecting NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers.
When Citrix disclosed the issue in June, the company said threat actors could only exploit it in denial-of-service attacks and stated that it had not observed any unmitigated exploitation. The following month, cybersecurity firm watchTowr demonstrated that successful exploitation could also allow attackers to gain remote code execution as root on unpatched NetScaler instances.
Citrix described the issue as a memory overflow vulnerability that “may lead to unpredictable behavior or denial of service and impacts NetScaler Gateway or AAA virtual server.”
Internet-Exposed NetScaler Instances
Internet threat watchdog Shadowserver currently tracks more than 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online. It is not known how many of those are honeypots, run vulnerable configurations, or have already been patched.
CISA Binding Operational Directive
On Monday, CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities (KEV) Catalog, ordering Federal Civilian Executive Branch agencies to secure all vulnerable Citrix appliances by August 29, as required under Binding Operational Directive BOD 26-04.
CISA did not share details on the attacks currently targeting the flaw, but its warning comes one week after security researchers and cybersecurity experts reported that the vulnerability was being exploited in opportunistic attacks that deploy web shells on compromised appliances.
Citrix has not updated the security advisory for CVE-2026-8452 to acknowledge that it is now being targeted in the wild.
Other Recently Disclosed NetScaler Vulnerabilities
The company also recently urged customers to immediately secure their systems against two other NetScaler vulnerabilities, CVE-2026-19490 and CVE-2026-19489, which remote, unauthenticated attackers can exploit in denial-of-service attacks or to bypass authentication. Those two flaws have not been tagged as exploited in the wild.
In March, Citrix asked administrators to patch two additional NetScaler vulnerabilities, CVE-2026-3055 and CVE-2026-4368, days before threat actors began abusing them.
Since November 2021, CISA has flagged 23 Citrix vulnerabilities as exploited in the wild, seven of which have also been used by ransomware groups.