CISA has issued an emergency directive ordering U.S. federal agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution (RCE) vulnerability. The vulnerability is being leveraged in real-world attacks, prompting CISA to set an urgent deadline of Saturday for remediation. The flaw affects Citrix NetScaler ADC and NetScaler Gateway appliances. Active exploitation in the wild makes this a critical priority for government and enterprise environments. Federal agencies are required to comply with CISA's Known Exploited Vulnerabilities (KEV) catalog directives. Failure to patch could expose sensitive government systems to unauthorized remote access. The urgency of the patch deadline reflects the severity and exploitation activity observed by CISA.
CVE-2026-8452 is a high-severity memory overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing) virtual servers. Initially disclosed by Citrix in June as only enabling denial-of-service (DoS) attacks, security firm watchTowr demonstrated in August that successful exploitation can also achieve unauthenticated remote code execution (RCE) as root on vulnerable instances. Threat actors are actively exploiting the flaw in 'pray and spray' attacks, deploying web shells on compromised appliances. CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities (KEV) Catalog on August 26, 2026, mandating Federal Civilian Executive Branch (FCEB) agencies to patch by August 29, 2026 under Binding Operational Directive (BOD) 26-04. Shadowserver tracks over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online. Two additional NetScaler vulnerabilities (CVE-2026-19490 and CVE-2026-19489) allow remote unauthenticated DoS or authentication bypass but have not yet been observed exploited in the wild. Two earlier NetScaler flaws (CVE-2026-3055 and CVE-2026-4368) were patched in March before being actively abused. Since November 2021, CISA has flagged 23 Citrix vulnerabilities as exploited in the wild, seven of which were also abused by ransomware gangs.
1. Immediately patch Citrix NetScaler ADC and NetScaler Gateway appliances against CVE-2026-8452 per the Citrix security advisory (CTX696604). Federal Civilian Executive Branch (FCEB) agencies must patch by August 29, 2026 per CISA's BOD 26-04 directive. 2. Also patch CVE-2026-19490 and CVE-2026-19489 (DoS and authentication bypass) and the previously disclosed CVE-2026-3055 and CVE-2026-4368. 3. Ensure NetScaler appliances are not unnecessarily exposed to the internet; review Shadowserver data to assess your exposure. 4. Check compromised appliances for web shells or signs of post-exploitation activity. 5. Monitor CISA's KEV Catalog and Citrix security advisories for updates on active exploitation. 6. If patching is not immediately possible, consider disabling Gateway VPN or AAA virtual server configurations as a temporary mitigation.
Web shells deployed on compromised Citrix NetScaler appliances