Recent Citrix NetScaler Vulnerability Exploited in the Wild
CISA has directed US government organizations to urgently remediate CVE-2026-8452, a high-severity flaw in Citrix NetScaler that is currently being actively attacked. Although initially described by the vendor as a potential denial-of-service issue, security researchers have confirmed that the vulnerability allows for unauthenticated remote code execution on devices configured as AAA virtual servers or Gateway VPN servers.
Active exploitation involves attackers deploying web shells and running reconnaissance commands, prompting CISA to add the bug to its Known Exploited Vulnerabilities catalog with an August 29 deadline. To mitigate the risk, administrators must update their appliances to fixed versions 14.1-72.61 (FIPS), 13.1-63.18, or 13.1-37.272.