Attackers are actively exploiting a Citrix NetScaler bug that was patched back in June, and CISA has now put it on the federal government’s must-fix list.
The agency added six flaws to its Known Exploited Vulnerabilities catalog on August 26. The NetScaler entry, CVE-2026-8452, is a memory overflow issue Citrix fixed on June 30 in versions 14.1-72.61, 13.1-63.18, and 13.1-37.272.
WatchTowr Labs analyzed the patch and showed the bug chains into unauthenticated remote code execution, publishing a proof of concept on August 14. Threat firms Defused and Previdian then logged attackers dropping web shells named x.php and z.php, and Previdian’s telemetry counted 36 exploitation attempts over 12 days from 12 unique IPs.
The rest of the catalog additions: CVE-2019-1068, a remote code execution bug in Microsoft SQL Server; CVE-2022-0995, an out-of-bounds memory write in the Linux kernel; CVE-2015-5287 and CVE-2015-3246, Red Hat ABRT and libuser privilege escalation flaws; and CVE-2021-23758, a deserialization flaw in Ajax.NET Professional enabling remote code execution.
Federal agencies have until August 29 to remediate. The pattern is familiar: proof-of-concept code goes public, and exploitation follows within days. Any internet-exposed NetScaler appliance should be patched now, not just in government networks.
