Citrix NetScaler CVE-2026-8452 is being exploited in the wild
The headline for the day is Citrix NetScaler. CVE-2026-8452, a memory buffer flaw in NetScaler ADC and NetScaler Gateway carrying a CVSS of 9.8, is now being exploited in the wild according to reporting from SecurityWeek and Help Net Security. This is a previously patched flaw, which means the fix already exists and the window to apply it is what separates an exposed appliance from a safe one.
CISA added CVE-2026-8452 to the Known Exploited Vulnerabilities catalog on 2026-08-26. NetScaler sits on the perimeter, terminates VPN and gateway traffic, and holds credentials. That combination makes it a favorite target. If you run NetScaler ADC or Gateway, patching this is a patch-now item, not a patch-eventually item.
Nine new KEV additions across two days
Beyond Citrix, CISA added several vulnerabilities to the KEV catalog on 2026-08-26 and 2026-08-27. None are flagged ransomware-linked in these entries, but KEV placement means active exploitation is confirmed.
The list spans web-facing servers, development tooling, and older Linux and Red Hat issues that attackers still find useful for privilege escalation.
- CVE-2023-49105, ownCloud improper authentication, CVSS 9.8, added 2026-08-27
- CVE-2026-53362, Linux Kernel, CVSS 7.8, added 2026-08-27
- CVE-2026-66384, JFrog Artifactory path traversal, CVSS 5.3, added 2026-08-27
- CVE-2019-1068, Microsoft SQL Server remote code execution, added 2026-08-26
- CVE-2021-23758, Ajax.NET Professional deserialization, CVSS 9.8, added 2026-08-26
- CVE-2022-0995, Linux Kernel out-of-bounds write, CVSS 7.8, added 2026-08-26
- CVE-2015-3246 and CVE-2015-5287, Red Hat Libuser and ABRT privilege escalation, added 2026-08-26
Hot movers worth attention
Among high-scoring exploited CVEs, CVE-2021-23758 (Ajax.NET Professional deserialization) tops the list with an EPSS of 0.8363 and is now KEV listed. Several ransomware-linked entries also rank high: CVE-2026-15409 in SonicWall SMA1000 (CVSS 10, ransomware-linked), CVE-2026-35273 in Oracle PeopleSoft PeopleTools (EPSS 0.9547, ransomware-linked), CVE-2026-45659 Microsoft SharePoint remote code execution (ransomware-linked), and CVE-2026-41940 in WebPros cPanel and WHM (EPSS 0.9853, ransomware-linked).
The SharePoint entry matters most to Microsoft 365 and on-prem administrators. It is KEV listed, ransomware-linked, and carries an EPSS of 0.7608. Tenable's edge infrastructure analysis reinforces the pattern: perimeter devices and gateways are where attackers concentrate, and CVE-2026-15409 shows up in that dataset.
What the press and advisories add
Qualys flagged CVE-2026-69414, a Windows Defender zero-day with no patch available, and noted CISA BOD 26-04 gives 14 days to act. Track that one for mitigation guidance since no fix is out yet.
On the industrial side, CISA published multiple ICS advisories on 2026-08-27, covering Applied Systems Engineering ASE2000, All-Line Fuel-Boss, Ebyte NA111-M, Mitsubishi Electric FA products and CNC series, and Xiiaozet LK100W. If any of these touch your OT environment, review them.
Do this first
Prioritize based on what is confirmed exploited and what is ransomware-linked.
- Patch Citrix NetScaler ADC and Gateway for CVE-2026-8452 now; it is exploited in the wild and KEV listed
- Confirm your Microsoft SharePoint patch state for CVE-2026-45659, which is ransomware-linked
- Check ownCloud instances against CVE-2023-49105 and Microsoft SQL Server against CVE-2019-1068
- Apply the mitigation guidance for CVE-2026-69414 since no patch exists yet
- Use the free Microsoft Patch Tracker from Siemserva by Senserva to rank open Microsoft patches by KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker to follow the daily KEV additions above
Sources
- SecurityWeek: Recent Citrix NetScaler Vulnerability Exploited in the Wild (2026-08-27)
- Help Net Security: Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) (2026-08-27)
- Tenable: Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter (2026-08-26)
- Qualys: CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days (2026-08-25)
- CISA Cybersecurity Advisories: CISA Adds Three Known Exploited Vulnerabilities to Catalog (2026-08-27)
- CISA Cybersecurity Advisories: Applied Systems Engineering ASE2000 V2 Communications Test Set (2026-08-27)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-08-28.
Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.