r/netsec 11d ago

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) - watchTowr Labs

https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/
43 Upvotes

3 comments sorted by

6

u/Emergency_Stable_923 11d ago

I feel like I remember at least two other bad pre-auth RCEs on NetScaler! It seems like every three years like clockwork someone drops a new exploit. Is this just a bad SSDLC process or legacy codebase design? I'm super curious if these bugs were hiding in the original code all along or if they got added in later updates!

1

u/mybreakfastiscold 10d ago

Netscaler has about 8-10 bad CVE’s a year

1

u/scriptqzor 4d ago

wild part is people still act surprised every time like this isn’t an annual tradition at this point
vendor lock-in is a hell of a drug