Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)
CVE Tools coverage
CISA has designated CVE-2026-8452 as actively exploited, adding it to its Known Exploited Vulnerabilities catalog following the public release of a proof-of-concept exploit by watchTowr Labs. This vulnerability affects Citrix NetScaler ADC and Gateway appliances configured with specific virtual servers, where a memory overflow can lead to denial of service or potentially unauthenticated remote code execution. While Citrix issued patches on June 30, 2026, attackers began leveraging the flaw shortly after the technical details were shared, deploying web shells for initial access.