The story is a familiar one: a vendor downplays a flaw, a researcher proves it's worse. Citrix rated CVE-2026-8452 an 8.8 memory overflow leading to denial of service and patched it quietly on June 30. On August 14, WatchTowr published analysis and proof-of-concept code showing the same bug is good for unauthenticated RCE on any appliance running as an AAA virtual server or a Gateway VPN server. Exploitation followed. Researchers watched attackers drop web shells named x.php and z.php, then run the usual discovery commands. That escalation is what pulled CISA in. The agency added the CVE to its Known Exploited Vulnerabilities catalog and set a federal remediation deadline of Saturday, August 29 — a tight turn even by KEV standards. If you run NetScaler ADC or Gateway with either of those configs exposed, the fixed builds are 14.1-72.61, 13.1-63.18, and 13.1-37.272 for FIPS. Patch, then go looking for x.php and z.php, because the deadline is the compliance date, not the day the exploitation started.