Citrix called it a denial of service. Researchers showed it was unauthenticated code execution
CVE-2026-8452 was patched on 30 June with an advisory describing unpredictable behaviour and DoS. WatchTowr published proof it gives unauthenticated remote code execution, and attackers were dropping web shells within days. CISA added it to KEV on 26 August with a three-day deadline. The patch existed for two months.




