CISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday.

Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap

Citrix NetScaler vulnerability tracked as CVE-2026-8452 has been exploited in the wild to deliver web shells, according to security firms.