-
-
Citrix Patched It as “Just a Crash.” A JPMorgan Researcher and watchTowr Proved It’s Pre-Auth RCE. Now CISA Wants It Fixed by Saturday.
Citrix patched CVE-2026-8452 in June and called it a denial-of-service bug. WatchTowr Labs and Bishop Fox have since shown it’s actually a pre-authentication remote code execution flaw in NetScaler’s SAML handling — and CISA confirmed active exploitation on August 26, giving federal agencies until August 29 to patch. Here’s how the root cause works, why this is the second exploited flaw from the same June patch bundle, and what to check before Saturday.
