A Patched Citrix Bug Is Getting Exploited Anyway

A Patched Citrix Bug Is Getting Exploited Anyway

"We already patched that" is one of those sentences that feels reassuring right up until someone shows you the exploit working on a fully patched box anyway. Citrix is having that exact week.

The Bug That Won't Stay Fixed

CVE-2026-8452 is a memory-overflow flaw in Citrix NetScaler ADC and NetScaler Gateway, the appliances companies use to run VPN gateways and application delivery at the network edge. Citrix already shipped a fix for it — and CISA still added the CVE to its Known Exploited Vulnerabilities catalog on August 26 after confirming attackers are actively using it in the wild, giving federal agencies until August 29 to patch or disconnect affected systems.

Citrix's own advisory calls it a high-severity issue that can cause "unpredictable or erroneous behavior" and denial-of-service conditions. Security firm WatchTowr disagrees with the "just a DoS bug" framing: their researchers demonstrated it can be chained into unauthenticated remote code execution, and attackers are already using it to drop web shells on appliances configured as AAA virtual servers or Gateway VPN servers.

Why "We Already Patched This" Isn't the Flex You Think It Is

Here's the gap nobody likes to talk about: a vendor shipping a patch and an organization actually applying it to every internet-facing appliance are two completely different events, sometimes separated by months. NetScaler boxes sit at the network perimeter by design, which makes them exactly the kind of target attackers scan for around the clock, patched-or-not.

This also isn't NetScaler's first rodeo. The same appliance family was at the center of CitrixBleed, one of the more brutal exploitation waves of the past few years, and state-linked and ransomware crews keep coming back to this product line because it works. If your patch cadence runs on a quarterly cycle, that cadence is currently a liability, not a process.

A patch that's available isn't the same thing as a patch that's applied — and attackers only need one of your appliances to miss the memo.

If you're not sure whether your edge infrastructure would survive a scan-and-exploit sweep like this one, our free security checklist walks through exactly what to audit first — grab it here.

Source: Help Net Security