CISA Orders Federal Agencies to Patch Critical Citrix NetScaler RCE Flaw by August 29 2026
CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog and requires U.S. federal agencies to apply patches for Citrix NetScaler before 29 August 2026. The flaw, initially classified as a denial-of-service issue, is already being exploited in the wild to achieve unauthenticated remote code execution with root privileges on unpatched devices.
The vulnerability affects NetScaler ADC and NetScaler Gateway when the appliance is configured as a VPN Gateway or as an AAA virtual server. These perimeter devices are frequently placed at the network edge to provide remote access, making them attractive targets for attackers seeking stealthy initial access. The attack surface expands further in deployments that use SAML, whether the device operates as a Service Provider or Identity Provider in single sign-on environments.
Citrix originally described the weakness as a memory overflow capable of causing erratic behavior and service denial. Subsequent public technical analysis revealed an exploitation chain that enables pre-authentication remote code execution with full root privileges, a significantly more severe outcome than simple denial of service.
Observed attack campaigns follow a spray-and-pray pattern, with attackers deploying webshells after successful compromise and issuing basic reconnaissance commands to map the environment. The potential reach is substantial: tens of thousands of NetScaler devices are exposed to the internet, including a meaningful number of publicly visible Gateway instances that typically trigger mass scanning once a reliable exploitation path emerges.
Defensive action requires immediate updating to corrected builds released by Citrix, such as version 14.1-72.61, 13.1-63.18, and for FIPS or NDcPP environments, 13.1-37.272 or later. Organizations should also conduct a full inventory of exposed instances, verify actual running versions and configurations, and hunt for indicators of compromise including webshells and reconnaissance artifacts. Where devices remain exposed as VPN Gateway or AAA servers, emergency patching windows and additional hardening measures such as network segmentation and restricted administrative access are strongly recommended.
Related articles
Stored XSS in Telegram Desktop Allows Silent Data Exfiltration via Chat Export
Researchers at ExPatch Vulnerability Research discovered a stored XSS vulnerability in Telegram Desktop that could be triggered when users exported chat history to HTML. The flaw resided in export_output_html.cpp where button text from inline keyboards was not passed through the SerializeString function, allowing arbitrary HTML and JavaScript to execute upon opening the exported file. Attackers could deliver the payload through a bot that never joined the target group, relying on message forwarding to reach victims. Once executed, the script exfiltrated all visible messages, chat metadata, and file paths to an attacker-controlled server while optionally replacing the page with a phishing form. Telegram issued a silent fix in Beta v6.9.4 and Stable v7.0.1 without publishing an advisory or assigning a CVE. The researchers refused the offered bounty and published the details after the patch to inform users about risks from previously exported files.
Cisco Confirms Active Exploitation of Critical Secure Email Gateway Flaw Allowing Root Command Execution
Cisco has confirmed active exploitation of a critical vulnerability in its Secure Email Gateway product that allows attackers to execute arbitrary commands with root privileges. The flaw, tracked as CVE-2026-76461 with a CVSS score of 9.8, stems from insufficient input validation in the message analysis logic of AsyncOS. Attackers can trigger the issue by sending a specially crafted email containing malicious SQL instructions, which leads to arbitrary SQL command execution and full root access on affected appliances. The vulnerability impacts physical and virtual deployments running AsyncOS versions 15.5 and earlier, 16.0, and 16.5. Patches are available in versions 15.5.5-0141, 16.0.4-302, and 16.5.0-780, while the Secure Email and Web Manager and Secure Web Appliance remain unaffected. CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 14 and set a September 17 remediation deadline for federal agencies.
Cisco ISE Affected by 42 Vulnerabilities Including Multiple Critical Flaws with Confirmed Exploitation
Cisco Identity Services Engine (ISE) has been found to contain 42 vulnerabilities across 15 security advisories released by Cisco Systems on September 16, 2026. Six advisories received the highest Critical rating, covering 21 individual vulnerabilities, while three were rated High and six Medium. One standout issue, CVE-2026-76460, allows attackers to bypass authentication on the management API via crafted HTTP requests and execute commands with root privileges. The flaw also impacts the Cisco ISE Passive Identity Connector (ISE-PIC). Cisco has urged immediate application of updates as some vulnerabilities are already being exploited in the wild. The product provides core network authentication and access control functions for enterprise environments.
CISA Adds Three Actively Exploited Vulnerabilities to KEV Catalog, Including Cisco ISE and Acronis Backup Flaws
The US Cybersecurity and Infrastructure Security Agency has added three vulnerabilities with confirmed in-the-wild exploitation to its Known Exploited Vulnerabilities catalog. The flaws affect Cisco Identity Services Engine, its Passive Identity Connector, and Acronis Backup plugins for cPanel and Plesk. All three entries carry a remediation deadline of September 19, 2026. The Cisco issue stems from insufficient authentication controls on an API endpoint that lets remote attackers bypass the web-based management interface. The Acronis vulnerability arises from overly permissive default settings in server-management plugins, enabling privilege escalation. Federal agencies have been directed to investigate potential compromises and apply mitigations without delay.