Security News

Urgent: Citrix NetScaler Flaw Under Active Attack — Patch Now

Security Week · 27 Aug 2026
Key Takeaway If your business uses Citrix NetScaler, contact your IT provider immediately to confirm the latest security patch has been applied.

The US Cybersecurity and Infrastructure Security Agency (CISA) is urging organisations to immediately patch a vulnerability in Citrix NetScaler, tracked as CVE-2026-8452. CISA has confirmed the flaw is being actively exploited in the wild, meaning attackers are already using it to target vulnerable systems rather than it being a theoretical risk.

Citrix NetScaler devices are widely used by businesses of all sizes to manage network traffic, load balancing, and secure remote access—including in Australia. Because these devices often sit at the edge of a company's network, a successful attack could give hackers a foothold to steal data, deploy ransomware, or move further into internal systems.

While the CISA advisory is directed at government agencies, the underlying message applies to any organisation running Citrix NetScaler: exploitation is happening now, and delaying patches significantly increases risk. Australian small businesses using Citrix products, either directly or through an IT provider, should check with their vendor or managed service provider to confirm whether their systems are affected and whether patches have been applied.

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.