Circuit Wire — a daily news update from the Circuit.

The U.S. Cybersecurity and Infrastructure Security Agency added a Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog on August 26 and gave federal civilian agencies three days, until August 29, to patch it. The bug, tracked as CVE-2026-8452, sits in NetScaler ADC and NetScaler Gateway appliances set up as a Gateway VPN or AAA virtual server. Those are the remote-access boxes that guard the edge of many corporate and government networks.

Citrix first disclosed the flaw on June 30 and rated it a denial-of-service problem. "We have not observed any unmitigated exploitation of this vulnerability," the company said at the time. That picture changed in August. Security firm watchTowr published analysis and proof-of-concept code on August 14, showing the same memory overflow could be pushed further, into unauthenticated remote code execution that runs as root on an unpatched appliance.

Attacks followed within days. Threat trackers Previdian and Defused reported seeing the flaw hit in the wild, with attackers dropping web shells and running simple discovery commands such as 'id' and 'echo' to map the systems they reached. Researchers characterized the early activity as broad, opportunistic scanning that sweeps the internet for any appliance still exposed. CISA has not detailed the intrusions, and its order landed about a week after researchers first flagged the exploitation.

The exposure is broad. Internet scanning group Shadowserver counts more than 22,000 NetScaler ADC appliances and close to 1,800 Gateway instances reachable online, though it cannot say how many run a vulnerable setup or are already fixed. Current patched builds also close a companion authentication-bypass flaw, CVE-2026-19490, that Citrix urged admins to install last week. The deadline set under Binding Operational Directive 26-04 has now passed, leaving any unpatched federal appliance out of compliance.

NetScaler has been a repeat target. Since November 2021, CISA has flagged 23 Citrix vulnerabilities as exploited in the wild, and ransomware crews have abused seven of them. Earlier in 2026, attackers began hitting a separate CitrixBleed-style NetScaler flaw within 24 hours of its public disclosure.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.