
CISA Adds Critical Citrix NetScaler Vulnerability to Exploited Catalog with Urgent Patch Deadline
Generalcybersecurityvulnerabilities
CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog, mandating U.S. federal agencies to patch Citrix NetScaler systems by 29 August 2026. The vulnerability, initially described as a denial-of-service issue, is now actively exploited to achieve unauthenticated remote code execution. No specific attack vectors or threat actors were detailed, but the flaw’s severity prompted the urgent directive. The affected product is Citrix NetScaler, with exploitation confirmed in the wild. The deadline applies exclusively to federal agencies under CISA’s authority.