Recent Citrix Netscaler Vulnerability Roundup: 2026-08-22

This is starting to become a series.

I was about to write up something about a specific recent Netscaler vulnerability, but as I was gathering information, I realized that there’s just been a deluge of exploited and not-yet-exploited critical vulnerabilities in Citrix Netscalers.

Let’s get into it.

CVE-2026-8452

CVSSv3: 9.8
Exploited: Unconfirmed, but probably soon

This is a memory corruption bug in the ADC and Gateway SAML handler.

Now this advisory is from June, but has seen recent research.

WatchTowr published a writeup on the vulnerability, doing their usual patch reversing.

Shortly thereafter, BishopFox built on that research and provided detection opportunities based on their detection tool.

CVE-2026-19489 and CVE-2026-19490

CVSSv4: 8.8, 9.3, respectively

This advisory is much more recent, from 2026-08-19T07:00:00Z.

19489 is a memory corruption vuln than can lead to denial of service. 19490 is an auth bypass. Both have specific preconditions that should be confirmed.

Rapid7 has a solid writeup and mitigation instructions.

Actions

Patch. But also, consider reviewing logs for the BishopFox indicators, especially if you have external-facing Netscalers with vulnerable configurations.

Note: this is staying in Vulnerabilities for right now until we have confirmation of exploitation, in which case we’ll do specific posts for those, with MISP events.

4 Likes