Citrix NetScaler Vulnerability CVE-2026-8452 Exploited in the Wild
- Severity
- HIGH
- Affected component
- citrix netscaler (npm)
- Patched version
- Not yet available
A high-severity vulnerability in Citrix NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-8452, is being actively exploited. Users of these products should upgrade immediately.
What happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation. This vulnerability, which stems from a memory overflow weakness, affects NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA virtual servers. While Citrix initially stated that the flaw could only be exploited for denial-of-service attacks, further analysis by watchTowr revealed that it can also lead to remote code execution as root on unpatched instances.
CISA has ordered government agencies to patch their Citrix NetScaler appliances by a specified deadline. The vulnerability was patched in versions 14.1-72.61 (FIPS), 13.1-63.18 and 13.1-37.272. Users should upgrade to one of these versions to mitigate the risk of exploitation.
What to do about it
- Upgrade to the latest version of Citrix NetScaler ADC and NetScaler Gateway.
- Ensure that your appliances are not configured as AAA virtual servers or Gateway VPN servers if possible.
- Monitor your systems for any signs of exploitation and report any suspicious activity to CISA.
- Consult the primary sources for the most up-to-date information and patches.
How 0Day would have caught this
citrix netscaler is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using Citrix NetScaler ADC or NetScaler Gateway, you may be affected. Check your configuration and upgrade to a patched version if necessary.
What should I do right now?
Upgrade to the latest version of Citrix NetScaler and monitor your systems for any signs of exploitation.
Has this been exploited in the wild?
Yes, there is evidence of active exploitation of this vulnerability.