CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 26, marking the inclusion of a previously patched Citrix NetScaler flaw tracked as CVE-2026-8452. The agency gave federal agencies a tight window of just three days to remediate the issue before the deadline expired on August 29.
Citrix disclosed the issue on June 30, describing the vulnerability as a “memory overflow vulnerability leading to unpredictable or erroneous behavior and denial of service.” The company released patches the same day for versions 14.1-72.61, 13.1-63.18, and 13.1-37.272. The specific trigger for the bug involves appliances configured as a Gateway, handling SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or operating as an AAA virtual server.
According to the company, researchers discovered the issue during internal product security strengthening exercises. At the time of disclosure, Citrix noted it had not observed unmitigated exploitation. However, the vulnerability has evolved rapidly since then.
Exploitation confirmed in the wild
Researchers at watchTowr Labs analyzed the patch and determined the memory overflow could be chained into full, unauthenticated remote code execution, a capability far beyond the initial denial-of-service description. The security firm published a technical writeup and working proof-of-concept code on August 14.
Related: North Korean Remote Workers Expand Beyond IT Jobs
Shortly after the technical details went public, attackers began actively targeting the vulnerability. Defused confirmed the first hits on its sensor infrastructure, and security company Previdian reported the first exploitation attempts on its own systems.
Previdian detailed the tactics used by the attackers, noting they were dropping web shells named “x.php” and “z.php.” The intruders ran discovery commands like “id” and “echo” to map out the compromised infrastructure. So far, Previdian identified three unique attack IPs originating from three different countries.
Citrix has not yet updated its official advisory to confirm in-the-wild exploitation, despite the reports from security firms. The remaining five vulnerabilities added to the KEV catalog include two Red Hat flaws (CVE-2015-3246 and CVE-2015-5287), a Microsoft SQL Server bug (CVE-2019-1068), an Ajax.NET deserialization flaw (CVE-2021-23758), and a Linux Kernel vulnerability (CVE-2022-0995).
