CISA Adds NetScaler ADC and Gateway Flaw to Actively Exploited List
CISA added CVE-2026-8452 in NetScaler ADC and NetScaler Gateway products to its Known Exploited Vulnerabilities catalog. U.S. federal civilian agencies must update the devices by August 29, 2026.

CISA NetScaler KEV expanded the Known Exploited Vulnerabilities catalog with CVE-2026-8452, a vulnerability in NetScaler ADC and NetScaler Gateway products. The U.S. agency added it to the catalog on August 26, 2026, confirming documented exploitation in the wild. U.S. federal civilian agencies must fix the affected systems by August 29, 2026.
The deadline applies exclusively to Federal Civilian Executive Branch agencies, so it is not a direct order for all organizations. For NetScaler device administrators, however, it is a signal that the update should not be delayed. A fix is available by updating to the recommended builds.
CISA NetScaler KEV: Which Versions Are Affected
According to the NetScaler security bulletin, CVE-2026-8452 is a memory overflow flaw. The vendor says it may lead to unpredictable behavior or denial of service.
Supported releases of NetScaler ADC and NetScaler Gateway are affected in the following versions:
- 14.1 before build 14.1-72.61,
- 13.1 before build 13.1-63.18,
- selected FIPS and NDcPP builds listed in the security bulletin.
NetScaler recommends updating to the recommended builds. Organizations should verify the specific edition and version of their devices against bulletin CTX696604, especially if they operate Gateway or AAA virtual server configurations.
Public Research Showed a Path to Root Privileges
Researchers at watchTowr Labs published a demonstration exploit. In a laboratory environment on a vulnerable NetScaler system, they achieved unauthenticated remote code execution with root privileges. According to their research, the successful path required a SAML configuration.
However, in its own CVE-2026-8452 bulletin, NetScaler does not directly describe the flaw as enabling remote code execution. watchTowr also uses cautious wording when associating the issue it examined with a specific CVE. Inclusion in KEV confirms active exploitation, but the available materials do not support the conclusion that CISA ordered remediation specifically for an RCE flaw confirmed by the vendor.
What NetScaler Device Administrators Should Do
For internet-facing, unpatched devices, the priority is to identify the version in use and deploy the recommended update build. NetScaler Gateway deployments, which are often used for remote access, and the Gateway or AAA virtual server configurations mentioned by the vendor are particularly relevant.
Publicly available demonstration code lowers the barrier for further exploitation attempts. The available information does not yet identify the attackers, specific victims, or the scope of the ongoing campaign. It is also important to monitor whether CISA or NetScaler publishes indicators of compromise, additional mitigations, or more precise confirmation of the relationship between the watchTowr research and CVE-2026-8452.
Sources
- NetScaler Security Bulletin CTX696604 – Confirms the flaw description, affected versions, and available fix builds.
- Canadian Centre for Cyber Security – Citrix security advisory AV26-645, Update 3 – Confirms that CISA added CVE-2026-8452 to KEV on August 26, 2026, and lists active exploitation as reported in open sources.
- watchTowr Labs – You’re Back In The Room – Documents a laboratory-demonstrated unauthenticated RCE chain and the acquisition of root privileges, while cautiously linking the research to CVE-2026-8452.
- BleepingComputer – Corroborates CISA’s deadline for U.S. federal civilian agencies: August 29, 2026.
Verified and updated: August 27, 2026 20:11



