security2 distinct publishers
Citrix called it a crash bug. It is unauthenticated RCE, and CISA gave agencies three days.
CVE-2026-8452 shipped as a June 30 denial-of-service fix. A WatchTowr proof of concept turned it into pre-auth code execution, and in-the-wild exploitation followed.
Reality
- Evidence80
- Adoption62
- Hype gap−30
- Incentives55