CISA Sets Aug 29 Deadline as Citrix NetScaler Flaw Hit

The US Cybersecurity and Infrastructure Security Agency has ordered federal agencies to patch a Citrix NetScaler vulnerability by Saturday, August 29, after security researchers showed the flaw is far more dangerous than first disclosed and is now being actively exploited.
The vulnerability, tracked as CVE-2026-8452, affects Citrix NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA virtual servers. Citrix disclosed and patched the memory-overflow bug on June 30, describing it only as capable of causing "unpredictable or erroneous behavior and denial of service." That assessment changed on August 14, when researchers at watchTowr Labs published a technical analysis and proof-of-concept code demonstrating that the same flaw could be chained into full, unauthenticated remote code execution as root.
Active exploitation began shortly after the watchTowr write-up went public. Threat intelligence firm Defused confirmed initial exploitation attempts, and security company Previdian said it observed attackers deploying web shells, named x.php and z.php, and running reconnaissance commands on compromised appliances from systems located in three different countries. Multiple researchers have described the pattern as "pray and spray" attacks, in which threat actors fire exploit attempts broadly at internet-facing devices rather than targeting specific organizations.
CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog on August 26 and, under Binding Operational Directive 26-04, ordered Federal Civilian Executive Branch agencies to secure all vulnerable NetScaler appliances by August 29. The directive applies specifically to US federal agencies, but security researchers are urging any organization running NetScaler ADC or Gateway to treat the patch as urgent.
Fixes are available in NetScaler versions 14.1-72.61, 13.1-63.18 and 13.1-37.272. As of the most recent reporting, Citrix's own security advisory had not been updated to acknowledge exploitation in the wild. Internet-scanning service Shadowserver has tracked more than 22,000 exposed NetScaler ADC appliances and nearly 1,800 exposed Gateway instances online; it is not known how many of those have already applied the patch.
Sources
- CitrixPrimary source
- watchTowr LabsPrimary source
- BleepingComputerSecondary
- Help Net SecuritySecondary
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- Two New Islands Rise by Anak Krakatau After 25-Hour Eruption
- New Gut Bacterium C. immunis Cut Visceral Fat in Obese Mice
- Meta's 100-Gram VR Glasses Cost $1,299.99, Ship Spring 2027
- Kurihara, 11, One Win From Youngest Asian Games Medal
- Yu Zidi, 13, Wins Third Asian Games Gold in 4:28.56 400 IM
- Haaland Passes Ronaldo and Zlatan With 64th Norway Goal
- Claude Leads 26% of Anthropic's AI R&D, Up From 1% in March
- SEC Grants 5-Year Exemption for Tokenized Stock Trading
Comments
No comments yet. Be the first.