A High-Severity Citrix Vulnerability is Being Exploited in the Wild, with Government Agencies Impacted
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to government organizations to immediately patch a critical vulnerability in Citrix’s NetScaler appliances. The flaw, known as CVE-2026-8452, was patched by Citrix on June 30, but it appears that threat actors have already started exploiting it in the wild.
This vulnerability affects specific versions of Citrix NetScaler, including 14.1-72.61 (FIPS), 13.1-63.18, and 13.1-37.272. It allows attackers to execute remote code on the affected system, potentially leading to a range of malicious activities, including data breaches and denial-of-service attacks.
According to WatchTowr, a cybersecurity firm that analyzed the vulnerability, it can be exploited for unauthenticated remote code execution. This means that attackers don’t need any prior access or credentials to launch an attack. In-the-wild exploitation was confirmed by Previdian and Defused shortly after the vulnerability details were made public.
The CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities (KEV) catalog, instructing agencies to address the issue by August 29. Notably, this is the second Citrix vulnerability exploited in recent months, following a similar vulnerability known as CVE-2026-8451.
The rapid pace at which threat actors are exploiting newly disclosed vulnerabilities highlights the importance of prompt patching and updating of systems. It’s crucial for organizations to stay vigilant and address security patches as soon as they become available.
In this case, government agencies and other organizations using Citrix NetScaler appliances should take immediate action to patch their systems. This includes verifying the version of NetScaler installed, applying the relevant patch, and ensuring that all appliances are configured securely.
For non-governmental organizations, while CVE-2026-8452 may not be as pressing an issue, it’s still essential to stay informed about this vulnerability and take steps to protect your systems. Regularly updating software and operating systems, as well as conducting security audits, can help mitigate the risk of exploitation.
As cybersecurity threats continue to evolve at an alarming rate, it’s clear that prompt action and proactive measures are necessary to prevent damage. By staying vigilant and addressing vulnerabilities promptly, we can reduce the likelihood of successful attacks and protect our sensitive information.
Source: SecurityWeek — 2026-08-27