A critical flaw in Citrix NetScaler appliances, first patched in June as a minor issue, has turned out to be far more serious. Attackers are now using it to break into unpatched systems without needing a username or password.
- What it is: CVE-2026-8452, a vulnerability in NetScaler ADC and Gateway devices that lets an attacker remotely run code on the appliance with no login required.
- Who is affected: Any business running a Citrix NetScaler ADC or Gateway appliance for remote access or load balancing that has not applied the August security update.
- What the risk is: Attackers are already exploiting this in the wild, planting hidden web shells that give them ongoing access to compromised appliances.
- What action is needed: Update to NetScaler build 14.1-73.32 or later (or 13.1-63.21 or later) immediately, and have the appliance checked for signs of compromise if it has been running an older version.
If your business uses Citrix NetScaler for remote access, we recommend confirming your appliance is patched as a priority this week.