A serious security flaw in Citrix NetScaler ADC and Gateway devices is being actively exploited by attackers right now, and government cyber security agencies are urging immediate action.
- What it is: A vulnerability (CVE-2026-8452) in Citrix NetScaler appliances lets attackers break in without needing a username or password, on devices set up for VPN or authentication services.
- Who is affected: Any business using a Citrix NetScaler ADC or Gateway appliance for remote access or VPN connections.
- What the risk is: Attackers have already been caught planting hidden web shells on compromised devices, giving them ongoing access to the network even after the initial break-in.
- What to do: Update to the latest Citrix-recommended firmware version immediately if you have not already. CISA has flagged this as a priority patch, with federal remediation deadlines already passed.
If your business uses Citrix NetScaler for remote access, we recommend confirming your appliance is on a patched version as a priority. Source: CISA Known Exploited Vulnerabilities Catalog.