This is starting to become a series.
I was about to write up something about a specific recent Netscaler vulnerability, but as I was gathering information, I realized that there’s just been a deluge of exploited and not-yet-exploited critical vulnerabilities in Citrix Netscalers.
Let’s get into it.
CVE-2026-8452
CVSSv3: 9.8
Exploited: Unconfirmed, but probably soon
This is a memory corruption bug in the ADC and Gateway SAML handler.
Now this advisory is from June, but has seen recent research.
WatchTowr published a writeup on the vulnerability, doing their usual patch reversing.
Shortly thereafter, BishopFox built on that research and provided detection opportunities based on their detection tool.
CVE-2026-19489 and CVE-2026-19490
CVSSv4: 8.8, 9.3, respectively
This advisory is much more recent, from 2026-08-19T07:00:00Z.
19489 is a memory corruption vuln than can lead to denial of service. 19490 is an auth bypass. Both have specific preconditions that should be confirmed.
Rapid7 has a solid writeup and mitigation instructions.
Actions
Patch. But also, consider reviewing logs for the BishopFox indicators, especially if you have external-facing Netscalers with vulnerable configurations.
Note: this is staying in Vulnerabilities for right now until we have confirmation of exploitation, in which case we’ll do specific posts for those, with MISP events.
