Citrix security advisory AV26-645 warns of active exploitation of CVE-2026-8451 and CVE-2026-8452

Published:

Citrix Security Advisory AV26-645: Critical Vulnerabilities in NetScaler Products

On June 30, 2026, Citrix issued a security advisory detailing critical vulnerabilities affecting several versions of its NetScaler ADC and NetScaler Gateway products. The vulnerabilities, identified as CVE-2026-8451 and CVE-2026-8452, have been confirmed to be actively exploited in the wild, raising significant concerns for users and administrators.

The affected products include:

  • NetScaler ADC and NetScaler Gateway – versions 14.1 before 14.1-72.61
  • NetScaler ADC and NetScaler Gateway – versions 13.1 before 13.1-63.18
  • NetScaler ADC FIPS – versions before 14.1-72.61 FIPS
  • NetScaler ADC FIPS and NDcPP – versions before 13.1-37.272

Exploitation Status

Recent open-source reports indicate that both CVE-2026-8451 and CVE-2026-8452 are being exploited by threat actors. This active exploitation underscores the urgency for organizations to address these vulnerabilities promptly.

Recommended Actions

The Cyber Centre strongly advises users and administrators of the affected Citrix products to review the security advisory and apply the necessary updates without delay. Ensuring that systems are running the latest versions is critical to mitigating the risks associated with these vulnerabilities.

For further details and to access the advisory, please visit the Citrix security advisory page.

Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

ShinyHunters resumes exploitation of Oracle PeopleSoft vulnerability, warns Mandiant

A new campaign by the hacking group ShinyHunters is exploiting a vulnerability in Oracle's PeopleSoft, as reported by Mandiant. This vulnerability, identified as CVE-2026-35273,...

CrowdStrike recognized as leader in Forrester Wave for proactive security platforms

CrowdStrike has been recognized as a Leader in The Forrester Wave: Proactive Security Platforms, Q3 2026, achieving the highest score in the Strategy category...

Microsoft tracks Storm-2570’s consistent tactics across multiple ransomware deployments

Microsoft has identified Storm-2570, a ransomware affiliate, as a significant threat actor employing consistent tactics across various ransomware deployments, including Qilin, DragonForce, Anubis, and...

Citrix NetScaler ADC and Gateway products affected by multiple critical CVEs

Citrix has disclosed multiple critical vulnerabilities affecting its NetScaler ADC and Gateway products, with at least two of these vulnerabilities, CVE-2026-88771 and CVE-2026-88772, reportedly...