Skip to content
Rush Commerce
Software & Dev4 min read

NetScaler CVE-2026-8452 hits KEV: patch by August 29

CISA added an actively exploited Citrix NetScaler flaw to KEV on August 26. Citrix called it a denial of service. Researchers say the same bug reaches code execution.

CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog on August 26, and one of them deserves your morning: CVE-2026-8452 in Citrix NetScaler ADC and NetScaler Gateway, with a federal remediation deadline of August 29. If you run a NetScaler appliance as a VPN gateway or an AAA server, that box is your front door and someone is already knocking. The reason this one slipped past a lot of patch queues is the label on it.

What actually happened

Citrix's bulletin CTX696604 rates CVE-2026-8452 at CVSS 8.8 and describes it as a "memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service." The vector is network-reachable, no authentication, no user interaction. Exploitation requires the appliance to be configured as a Gateway — SSL VPN, ICA Proxy, CVPN, or RDP Proxy — or as an AAA virtual server. That is most of the reason anyone buys one.

Fixed versions, per Citrix:

  • 14.1-72.61 and later
  • 13.1-63.18 and later
  • 14.1-72.61 FIPS and later
  • 13.1-37.272 and later (FIPS and NDcPP)

Now the part that changes the priority. On August 14, researchers at watchTowr Labs published an analysis of a pre-auth heap overflow in NetScaler's SAML signature handling — attacker-controlled data from a ds:SignedInfo element copied into a fixed-size buffer during canonicalization, with an oversized PrefixList attribute producing a write-what-where primitive and a hijacked function pointer. They walk it to remote code execution. They also say plainly that they believe this is CVE-2026-8452 based on the "memory overflow" description, because Citrix's advisory doesn't map individual CVEs cleanly. Treat the attribution as strong but not confirmed. Treat the patch as mandatory either way.

Exploitation in the wild is not theoretical. The Hacker News reports attackers dropping web shells named x.php and z.php and running discovery commands, with telemetry showing 36 exploitation attempts across 12 days from infrastructure in ten countries.

The other five KEV additions: CVE-2019-1068 (Microsoft SQL Server RCE, also due August 29), CVE-2022-0995 (Linux kernel out-of-bounds write), CVE-2015-5287 (Red Hat ABRT privilege escalation), CVE-2015-3246 (Red Hat libuser race condition), and CVE-2021-23758 (Ajax.NET Professional deserialization) — those four due September 9.

Why a "denial of service" rating matters for your business

Most small teams triage by impact class. RCE jumps the queue. DoS on an appliance gets a ticket and a maintenance window three weeks out, because the worst case reads as "it falls over and we reboot it."

That heuristic is what got exploited here. The vendor's own description said DoS. Independent research says the same memory corruption reaches code execution before authentication. Between those two readings sits a gateway appliance that terminates your VPN, brokers your SSO, and sees credentials for everything behind it. Getting that wrong doesn't cost you an outage. It costs you the network.

Four things today:

Find out what you actually run. NetScaler often arrives through a managed service provider or an acquisition, not a purchase order. Check the ADC/Gateway version in the management UI or via show version.

Patch to the fixed builds above. Not next window. The federal deadline is August 29 and that number exists because exploitation is confirmed.

Check whether Gateway or AAA vserver is configured. If neither is, you are outside the exploitation prerequisite and can breathe — then patch anyway, because configurations change and nobody re-checks CVEs when they do.

Assume compromise if you were exposed and unpatched. Look for x.php, z.php, and anything else unexpected in web-servable paths. Then rotate what the appliance could reach: session secrets, LDAP or AD service accounts, certificates, and anything stored in its config.

We say a version of this every few weeks, and it is still the whole lesson: severity ratings are a vendor's opinion about the worst case they tested. Exploitation evidence is a fact. When CISA publishes a deadline, that is the fact talking.

Key takeaways

  • CVE-2026-8452 (CVSS 8.8) in Citrix NetScaler ADC and Gateway was added to CISA's KEV catalog August 26 with a federal deadline of August 29
  • Citrix describes it as a memory overflow causing denial of service; watchTowr Labs published a pre-auth heap-overflow-to-RCE analysis it believes maps to this CVE
  • Exploitation requires the appliance configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server — the common deployments
  • Fixed in 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS, and 13.1-37.272 and later
  • Reported in-the-wild activity includes web shells named x.php and z.php, with 36 attempts logged over 12 days from ten countries
  • Patching alone doesn't undo prior access — rotate session secrets, directory service accounts, and certificates the appliance could reach

Nobody owns your edge appliances until someone is named. We track KEV additions against the actual inventory our clients run — gateways, load balancers, self-hosted git, the boxes that came with an acquisition — so a vendor's "denial of service" rating never becomes your incident. See what we monitor and operate, or tell us what's facing the internet and who patches it.

Sources: Citrix CTX696604, watchTowr Labs, The Hacker News.

  • #citrix
  • #netscaler
  • #cve
  • #cisa-kev
  • #patching
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.