CISA Warns of Citrix NetScaler ADC and Gateway Vulnerability Exploited in Attacks
Brief
The U. S. Cybersecurity and Infrastructure Security Agency has added a critical Citrix NetScaler ADC and NetScaler Gateway security flaw, tracked as CVE-2026-8452 , to its Known Exploited Vulnerabilities catalog after confirming exploitation in attacks.
The vulnerability was added on August 26, 2026, and federal civilian executive branch agencies must apply the vendor-recommended mitigations by August 29, 2026.
CISA’s listing signals that the issue presents an immediate operational risk, particularly for organizations that expose NetScaler appliances to the internet.
CVE-2026-8452 is an improper restriction of operations within the bounds of a memory buffer vulnerability, classified as CWE-119. The flaw affects Citrix NetScaler ADC and NetScaler Gateway products. It can allow an unauthenticated attacker to trigger a denial-of-service condition.
