THE Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning for government organizations to address a high-severity vulnerability (CVE-2026-8452) in Citrix NetScaler, which is actively being exploited. This vulnerability can allow unauthenticated remote code execution, as analyzed by cybersecurity firm WatchTowr, which published exploit details on August 14.
CISA included this flaw in its Known Exploited Vulnerabilities catalog on August 26, advising agencies to mitigate it by August 29. This is the second Citrix vulnerability exploited shortly after public disclosure, following CVE-2026-8451.