The U.S. Cybersecurity and Infrastructure Security Agency has ordered federal civilian agencies to secure vulnerable Citrix NetScaler appliances against an actively exploited flaw by Saturday, BleepingComputer reports. The issue is tracked as CVE-2026-8452, and CISA added it to its Known Exploited Vulnerabilities catalog with an August 29 remediation deadline for Federal Civilian Executive Branch agencies. According to BleepingComputer, the vulnerability is a high-severity memory overflow issue affecting NetScaler ADC and NetScaler Gateway appliances when they are configured with Gateway VPN or Authentication, Authorization, and Auditing virtual servers. That configuration detail matters: the report does not say every NetScaler deployment is affected, only appliances in the specified Gateway VPN or AAA virtual-server setup. Citrix had previously described the flaw as one that could lead to unpredictable behavior or denial of service, BleepingComputer reports. The company also said at the time that it had not observed unmitigated exploitation of the vulnerability. The risk assessment changed after security firm watchTowr showed in August that successful exploitation could also permit remote code execution as root on unpatched NetScaler instances, according to the report. CISA’s KEV listing indicates the agency considers the flaw actively exploited, but BleepingComputer says CISA did not provide details on the current attacks. The warning followed reports from security researchers and cybersecurity experts that the vulnerability was being used in broad “pray and spray” activity to place web shells on compromised appliances. The internet-exposure surface is material, but the precise vulnerable population is unknown. BleepingComputer cites Shadowserver as tracking more than 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online. The report also notes important caveats: those counts do not establish how many exposed systems are honeypots, how many have the vulnerable configuration, or how many have already been patched. Citrix had not updated its CVE-2026-8452 advisory to acknowledge in-the-wild exploitation at the time of BleepingComputer’s report. The company also recently urged customers to secure systems against two other NetScaler vulnerabilities, CVE-2026-19490 and CVE-2026-19489, which BleepingComputer says can be exploited by remote, unauthenticated attackers for denial-of-service attacks or authentication bypass, though those two flaws had not been tagged as exploited in the wild. The broader pattern is why this is getting federal urgency. BleepingComputer reports that since November 2021, CISA has flagged 23 Citrix vulnerabilities as exploited in the wild, with seven also abused by ransomware gangs. For operators, the immediate question is narrower than the history: whether any NetScaler ADC or Gateway appliances with the affected Gateway VPN or AAA virtual-server configurations remain unpatched before the August 29 federal deadline. Who benefits: Federal agencies and private operators that already patched or can quickly validate exposure reduce the window for opportunistic exploitation. Security vendors and incident responders also benefit from a clear KEV-driven prioritization signal. Who's exposed: Organizations running unpatched NetScaler ADC or NetScaler Gateway appliances configured with Gateway VPN or AAA virtual servers are the exposed group described in the report. The provided material does not establish how many internet-facing instances are actually vulnerable.