Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)
ID: be71580c-03ab-5ae8-8bd9-6327127081e3
STIX ID: report--be71580c-03ab-5ae8-8bd9-6327127081e3
Feed Name: Help Net Security
Threat Score
CISA added CVE-2026-8452—an unauthenticated memory-overflow in Citrix NetScaler ADC/Gateway that can be chained to remote code execution—to its KEV catalog and required rapid remediation. A public patch and PoC were released; researchers and vendors observed active exploitation where attackers dropped web shells ("x.php", "z.php") and ran discovery commands, and five additional older vulnerabilities were also added to the KEV list.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
