Cybersecurity

CISA Sets Aug 29 Deadline as Citrix NetScaler Flaw Hit

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

CISA Sets Aug 29 Deadline as Citrix NetScaler Flaw Hit
Photo: NewUJ
0 0
XWhatsAppTelegramLinkedIn

The US Cybersecurity and Infrastructure Security Agency has ordered federal agencies to patch a Citrix NetScaler vulnerability by Saturday, August 29, after security researchers showed the flaw is far more dangerous than first disclosed and is now being actively exploited.

The vulnerability, tracked as CVE-2026-8452, affects Citrix NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA virtual servers. Citrix disclosed and patched the memory-overflow bug on June 30, describing it only as capable of causing "unpredictable or erroneous behavior and denial of service." That assessment changed on August 14, when researchers at watchTowr Labs published a technical analysis and proof-of-concept code demonstrating that the same flaw could be chained into full, unauthenticated remote code execution as root.

Active exploitation began shortly after the watchTowr write-up went public. Threat intelligence firm Defused confirmed initial exploitation attempts, and security company Previdian said it observed attackers deploying web shells, named x.php and z.php, and running reconnaissance commands on compromised appliances from systems located in three different countries. Multiple researchers have described the pattern as "pray and spray" attacks, in which threat actors fire exploit attempts broadly at internet-facing devices rather than targeting specific organizations.

CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog on August 26 and, under Binding Operational Directive 26-04, ordered Federal Civilian Executive Branch agencies to secure all vulnerable NetScaler appliances by August 29. The directive applies specifically to US federal agencies, but security researchers are urging any organization running NetScaler ADC or Gateway to treat the patch as urgent.

Fixes are available in NetScaler versions 14.1-72.61, 13.1-63.18 and 13.1-37.272. As of the most recent reporting, Citrix's own security advisory had not been updated to acknowledge exploitation in the wild. Internet-scanning service Shadowserver has tracked more than 22,000 exposed NetScaler ADC appliances and nearly 1,800 exposed Gateway instances online; it is not known how many of those have already applied the patch.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.