CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

The US Government Faces a Deadline to Patch Critical Citrix Vulnerability

A critical security flaw in Citrix NetScaler appliances has been identified as actively exploited by threat actors, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to order federal agencies to patch their systems by Saturday. The vulnerability, tracked as CVE-2026-8452, allows attackers to gain remote code execution as root on unpatched instances.

Citrix NetScaler appliances are used by thousands of organizations worldwide, including government agencies, to provide secure access to applications and resources over the internet. However, a recent discovery has revealed that these devices are vulnerable to a memory overflow weakness that can be exploited to disrupt service or gain unauthorized access. Initially, Citrix stated that the flaw could only be exploited in denial-of-service (DoS) attacks, but cybersecurity firm watchTowr later demonstrated that it can also lead to remote code execution as root.

The CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities (KEV) Catalog and ordered Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by August 29. The agency’s warning comes after security researchers and cybersecurity experts flagged the vulnerability as actively exploited in “pray and spray” attacks that deploy web shells on compromised appliances.

The situation highlights the importance of timely patching and regular monitoring of network devices. With over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online, it’s crucial for organizations to take immediate action to prevent potential breaches. Citrix has yet to update its security advisory for CVE-2026-8452 to acknowledge the active exploitation.

This is not an isolated incident; since November 2021, CISA has flagged 23 Citrix vulnerabilities as exploited in the wild, with seven of them also abused by ransomware gangs. This underscores the need for organizations to stay vigilant and prioritize patching and vulnerability management.

In light of this development, it’s essential for system administrators to review their network configurations and ensure that all vulnerable Citrix appliances are patched before the deadline. Regular security audits and monitoring can help detect potential issues early on, preventing costly breaches and minimizing downtime.


Source: Bleeping Computer — 2026-08-27