Skip to content
feed: live
>_0dayNews
citrix
● Breaking

Patch by Friday: Citrix NetScaler CVE-2026-8452 in KEV

Citrix NetScaler CVE-2026-8452 (CVSS 9.8) is confirmed exploited in the wild. CISA's KEV listing sets a federal patch deadline of August 29, 2026.

Patch by Friday: Citrix NetScaler CVE-2026-8452 in KEV
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·2 min read

CVE-2026-8452 landed in CISA’s Known Exploited Vulnerabilities catalog on August 26. Federal agencies have until August 29 to patch. That’s the actual deadline — not a suggestion, not a soft target. If you run NetScaler in a Gateway or AAA configuration, this is your immediate priority.

What the flaw is

CVE-2026-8452 is a memory buffer overflow in Citrix NetScaler ADC and NetScaler Gateway. NVD rates it CVSS 9.8 critical. According to Citrix’s advisory CTX696604, the vulnerability affects appliances configured as:

  • Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy)
  • AAA virtual server

The flaw can lead to unpredictable behavior and denial of service. CISA’s KEV listing confirms active exploitation in the wild, which makes the CVSS score secondary — the relevant fact is that someone is already using this.

What to do

Step one: Determine whether your NetScaler appliance is operating as a Gateway or AAA virtual server. Appliances not in those roles are not in scope for this specific vulnerability.

Step two: Apply Citrix’s patches. Full guidance — including affected build ranges and mitigation steps — is in Citrix advisory CTX696604. Do not skip to the patching section without reading the scope conditions first.

Step three (federal agencies): This falls under BOD 26-04. The August 29 deadline is mandatory. CISA has also attached forensics triage requirements to this KEV entry; review CISA’s BOD 26-04 implementation guidance for specifics.

For cloud-deployed NetScaler, CISA’s standard direction applies: follow BOD 26-04 guidance for cloud services, or discontinue use if mitigations are unavailable.

Context

This is the second significant NetScaler advisory this month. Earlier in August, Citrix patched a critical authentication bypass, CVE-2026-19490, in the same product line. Two critical KEV entries in one product, one month — if you’ve been carrying technical debt on your NetScaler fleet, now is not the time to carry it further.

SecurityWeek reported that CISA has urged government agencies to immediately patch. The exploited-in-wild confirmation is not qualified; CISA’s threshold for KEV addition requires confirmed evidence of active exploitation.

The CVE entry for this flaw is on our KEV tracker and at /cve/CVE-2026-8452/.

Related: Citrix Bleed: A Memory Leak That Bypassed MFA · What Is the CISA KEV Catalog? · What Is EPSS?

Related CVEs
  • [ CRITICAL ]CVE-2026-8452Citrix NetScaler ADC and Gateway Memory Buffer Overflow

Found this useful? Share it.