Citrix security advisory (AV26-645) – Update 3

Serial number: AV26-645
Date: June 30, 2026
Updated: August 26, 2026

On June 30, 2026, Citrix published a security advisory to address critical vulnerabilities in the following products:

  • NetScaler ADC and NetScaler Gateway - versions 14.1 before 14.1-72.61
  • NetScaler ADC and NetScaler Gateway - versions 13.1 before 13.1-63.18
  • NetScaler ADC FIPS – versions before 14.1-72.61 FIPS
  • NetScaler ADC FIPS and NDcPP – versions before 13.1-37.272

Update 1

Open-source reporting indicates that CVE-2026-8451 is being exploited.

Update 2

Open-source reporting indicates that CVE-2026-8452 is being exploited in the wild.

Update 3

On August 26, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-8452 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.

Date modified: