Patch by Friday: Citrix NetScaler CVE-2026-8452 in KEV
Citrix NetScaler CVE-2026-8452 (CVSS 9.8) is confirmed exploited in the wild. CISA's KEV listing sets a federal patch deadline of August 29, 2026.

CVE-2026-8452 landed in CISA’s Known Exploited Vulnerabilities catalog on August 26. Federal agencies have until August 29 to patch. That’s the actual deadline — not a suggestion, not a soft target. If you run NetScaler in a Gateway or AAA configuration, this is your immediate priority.
What the flaw is
CVE-2026-8452 is a memory buffer overflow in Citrix NetScaler ADC and NetScaler Gateway. NVD rates it CVSS 9.8 critical. According to Citrix’s advisory CTX696604, the vulnerability affects appliances configured as:
- Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy)
- AAA virtual server
The flaw can lead to unpredictable behavior and denial of service. CISA’s KEV listing confirms active exploitation in the wild, which makes the CVSS score secondary — the relevant fact is that someone is already using this.
What to do
Step one: Determine whether your NetScaler appliance is operating as a Gateway or AAA virtual server. Appliances not in those roles are not in scope for this specific vulnerability.
Step two: Apply Citrix’s patches. Full guidance — including affected build ranges and mitigation steps — is in Citrix advisory CTX696604. Do not skip to the patching section without reading the scope conditions first.
Step three (federal agencies): This falls under BOD 26-04. The August 29 deadline is mandatory. CISA has also attached forensics triage requirements to this KEV entry; review CISA’s BOD 26-04 implementation guidance for specifics.
For cloud-deployed NetScaler, CISA’s standard direction applies: follow BOD 26-04 guidance for cloud services, or discontinue use if mitigations are unavailable.
Context
This is the second significant NetScaler advisory this month. Earlier in August, Citrix patched a critical authentication bypass, CVE-2026-19490, in the same product line. Two critical KEV entries in one product, one month — if you’ve been carrying technical debt on your NetScaler fleet, now is not the time to carry it further.
SecurityWeek reported that CISA has urged government agencies to immediately patch. The exploited-in-wild confirmation is not qualified; CISA’s threshold for KEV addition requires confirmed evidence of active exploitation.
The CVE entry for this flaw is on our KEV tracker and at /cve/CVE-2026-8452/.
Related: Citrix Bleed: A Memory Leak That Bypassed MFA · What Is the CISA KEV Catalog? · What Is EPSS?
- [ CRITICAL ]CVE-2026-8452Citrix NetScaler ADC and Gateway Memory Buffer Overflow
Found this useful? Share it.

