Citrix called CVE-2026-8452 a denial-of-service risk in June. In August, watchTowr proved it was a pre-auth heap overflow giving root on NetScaler ADC and Gateway. Exploitation followed within days. The flaw, the web shells, and why severity labels shouldn’t drive your patch queue.