Web_Logo
Remote Support
Security Alert: Citrix NetScaler Flaw Under Active Attack
Home » Security Alerts  »  Security Alert: Citrix NetScaler Flaw Under Active Attack

Security Alert: Citrix NetScaler Flaw Under Active Attack

A previously patched security flaw in Citrix NetScaler ADC and NetScaler Gateway devices, commonly used by businesses for secure remote access and VPN connections, is now being actively exploited by attackers.

  • What it is: CVE-2026-8452, a memory-handling flaw in NetScaler ADC and Gateway software that Citrix patched in June 2026.
  • Who is affected: Any business running a NetScaler ADC or Gateway appliance that has not applied the June 2026 patch (versions before 14.1-72.61, 13.1-63.18 or 13.1-37.272).
  • What the risk is: Security researchers have shown attackers can use the flaw to gain full remote control of an unpatched device, not just disrupt service as first thought. Attackers are already planting web shells on compromised systems.
  • What to do: Confirm your NetScaler devices are running a patched version. The US Cybersecurity and Infrastructure Security Agency has ordered government agencies to patch by 29 August.

We recommend any business running Citrix NetScaler confirm patch status today, given attackers are actively exploiting unpatched systems.