Citrix NetScaler Pre-Auth RCE Actively Exploited in the Wild
CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog with a 3-day remediation deadline of August 29, after confirmation that attackers are actively exploiting the flaw to deploy web shells on unpatched NetScaler appliances.
Citrix originally disclosed CVE-2026-8452 on June 30 as a memory overflow vulnerability leading to denial of service on appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Patches shipped the same day in versions 14.1-72.61, 13.1-63.18, and 13.1-37.272. At the time, Citrix stated it had not observed exploitation.
The severity escalated dramatically on August 14 when watchTowr Labs published a technical analysis and working proof-of-concept demonstrating that the flaw could be chained into full, unauthenticated remote code execution, well beyond the denial-of-service impact Citrix originally described. The NVD rates this CVE at 9.8 (Critical). Within days, threat intelligence firm Defused confirmed the first exploitation hits on its sensors. Previdian reported attackers dropping web shells named "x.php" and "z.php" and running discovery commands across compromised systems from at least three unique IPs in three different countries.
Notably, Citrix's own advisory has still not been updated to acknowledge in-the-wild exploitation, despite CISA's KEV listing and multiple independent confirmations.
NetScaler Authentication Bypass Still Unlisted
A second critical NetScaler vulnerability, CVE-2026-19490 (CVSS 9.3), remains unlisted on the KEV catalog. This authentication bypass, disclosed August 19, allows an unauthenticated remote attacker to circumvent login controls entirely. No public exploitation has been confirmed yet, but given CVE-2026-8452's trajectory from disclosure to active exploitation in under two weeks, the window for preemptive patching is narrow.
Additional KEV Additions
CISA's August 26 KEV batch also includes five other vulnerabilities: Microsoft SQL Server RCE (CVE-2019-1068), a Linux Kernel out-of-bounds write (CVE-2022-0995), two Red Hat privilege escalation flaws from 2015 (CVE-2015-3246, CVE-2015-5287), and an Ajax.NET deserialization vulnerability (CVE-2021-23758). All carry August 29 or September 9 remediation deadlines.
So What / Action
If you run NetScaler ADC or Gateway and have not patched since June 30, treat this as an emergency. Patch to 14.1-72.61, 13.1-63.18, or 13.1-37.272 immediately. Check for indicators of compromise: web shells named x.php or z.php in web directories, unexpected process execution from the NetScaler service account, and anomalous outbound connections. If you cannot patch by Saturday, consider isolating Gateway and AAA virtual servers until remediation is complete. Also patch CVE-2026-19490 while you are at it. Citrix's track record on timely advisory updates is poor; do not wait for their confirmation to act.

