CVE-2026-8452: The NetScaler 'DoS Patch' That Was Actually Unauthenticated RCE
A NetScaler bug Citrix classified as denial-of-service in June turned out to be unauthenticated remote code execution, and CISA has confirmed active exploitation. Patching closes the door, but it doesn't check who already walked through it.














