Citrix NetScaler Vulnerability (CVE-2026-8452) Exploited After Patch

www.news4hackers.com-citrix-netscaler-vulnerability-cve-2026-8452-exploited-after-patch-citrix-netscaler-vulnerability-cve-2026-8452-exploited-after-patch

CISA incorporated six vulnerabilities into its Known Exploited Vulnerabilities (KEV) list, including a previously addressed Citrix NetScaler ADC and Gateway flaw designated CVE-2026-8452 that is now being actively exploited.

CISA’s KEV Update

CISA incorporated six vulnerabilities into its Known Exploited Vulnerabilities (KEV) list, including a previously addressed Citrix NetScaler ADC and Gateway flaw designated CVE-2026-8452 that is now being actively exploited. The agency issued an advisory on August 26, mandating federal agencies to address the issue by August 29.

Vulnerability Details

The vulnerability was initially disclosed by Citrix on June 30, 2026, categorized as a memory overflow flaw causing erratic behavior and service disruptions. Patches were released on the same day for versions 14.1-72.61, 13.1-63.18, and 13.1-37.272. The flaw manifests when appliances operate as Gateways supporting SSL VPN, ICA Proxy, CVPN, or RDP Proxy configurations, or as AAA virtual servers.

WatchTowr Labs Analysis

Citrix noted the issue emerged during internal security assessments, with no confirmed exploitation observed at the time. Researchers at watchTowr Labs reverse-engineered the patch and identified potential for chaining the vulnerability into unauthenticated remote code execution, surpassing the denial-of-service impact initially reported.

On August 14, the team released a technical analysis and proof-of-concept code. Within days, threat actors began leveraging the flaw, as confirmed by Defused through its EX customer sensor network.

Exploitation Attempts

Security firm Previdian reported detecting exploitation attempts targeting CVE-2026-8452, noting adversaries deploying web shells named x.php and z.php while executing reconnaissance commands such as id and echo to identify compromised systems. The firm documented three distinct IP addresses originating from separate geographic regions.

Notably, Citrix’s official advisory remains unchanged, lacking acknowledgment of active exploitation.

Other KEV Vulnerabilities

The remaining five vulnerabilities in the KEV update encompass a range of older and recent software flaws, including two Red Hat issues (CVE-2015-3246 and CVE-2015-5287), a Microsoft SQL Server vulnerability (CVE-2019-1068), an Ajax.NET deserialization flaw (CVE-2021-23758), and a Linux Kernel vulnerability (CVE-2022-0995).

Implications and Risks

The Citrix NetScaler vulnerability analysis highlighted by watchTowr Labs underscores the risks of unpatched systems and the evolving tactics of threat actors exploiting previously mitigated flaws.



About Author

en_USEnglish