CISA has added a critical memory overflow vulnerability (CVE-2026-8452, CVSS 9.8) in Citrix NetScaler ADC and Gateway to its KEV catalog due to active exploitation. Affected versions include NetScaler ADC 13.1 before 13.1-37.272, 13.1-63.18, and 14.1 before 14.1-72.61. Organizations must immediately upgrade to the fixed versions 13.1-37.272, 13.1-63.18, or 14.1-72.61 as specified by the NVD.
CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, that is being exploited in the wild. The agency published the alert on August 26 and gave federal agencies until August 29 to remediate it. About CVE-2026-8452 Citrix disclosed the issue on June 30, 2026, describing CVE-2026-8452 as a “memory overflow vulnerability leading to unpredictable or erroneous behavior and denial … More → The post Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) appeared first on Help Net Security .