Back to Blog
CVE-2026-8452: Citrix NetScaler — Unauthenticated RCE Enables Web Shells (August 2026)
vulnerabilities

CVE-2026-8452: Citrix NetScaler — Unauthenticated RCE Enables Web Shells (August 2026)

breachwire TeamAug 28, 20262 min read

CVE-2026-8452 — Citrix NetScaler

CVE-2026-8452 is a critical vulnerability in Citrix NetScaler ADC and Gateway, enabling unauthenticated remote code execution (RCE) on affected appliances. Following a public technical writeup and proof-of-concept exploit release on August 14, 2026, active exploitation began globally. Attackers are deploying web shells and running discovery commands, confirming real-world impact. Severity is critical; immediate action is required.

Attack Vector

Attackers exploit CVE-2026-8452 remotely without authentication, targeting exposed NetScaler ADC and Gateway instances. The exploit allows arbitrary command execution, with observed activity including deployment of web shells named x.php and z.php. Attackers also run commands such as 'id' and 'echo' to enumerate compromised environments. Multiple threat actors from different countries are leveraging this vector, often as soon as a vulnerable system is identified.

Who Is at Risk

All organizations running unpatched Citrix NetScaler ADC and Gateway appliances are at risk, regardless of deployment size or sector. Both on-premises and cloud-exposed instances are vulnerable. Confirmed victims include Citrix NetScaler customers globally, with no sector immunity observed.

Patch & Mitigate

  • Patch: Apply the official Citrix security update for CVE-2026-8452 immediately. Refer to Citrix advisories for exact fixed versions.
  • Workaround: No reliable workaround is available; patching is mandatory.
  • Detect: Review web server logs for unexpected files named x.php or z.php, and monitor for execution of 'id' or 'echo' commands. Inspect for anomalous outbound connections or new administrative accounts.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers exploit a remote service vulnerability to gain entry without authentication.
  • TA0005 — Defense Evasion: Web shells (x.php, z.php) are deployed to maintain persistence and evade detection.

Source: https://www.helpnetsecurity.com/2026/08/27/netscaler-adc-gateway-cve-2026-8452/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: