JPCERT/CC, Japan's computer emergency response coordination centre, published alert JPCERT-AT-2026-0024 on 15 August about CVE-2026-8452 in NetScaler ADC and NetScaler Gateway, and stated that as of that date it had confirmed no information indicating exploitation 1. NetScaler ADC balances and delivers application traffic; NetScaler Gateway is the box remote staff sign in through. Both sit at the edge of the network, in front of everything else.
WatchTowr Labs, an offensive-security research firm, had published technical analysis and a proof of concept the day before, showing code execution without a login against appliances configured as SAML service providers or identity providers. SAML, Security Assertion Markup Language, is the protocol by which one system vouches for a user's identity to another, so the exposed configuration is the one doing single sign-on for everybody else.
Read the alert's wording precisely. A published proof of concept is not exploitation, and JPCERT/CC described its own information state on one day rather than the state of the world. This beat has seen how far apart those two things can sit: a French detection firm logged attacks against a Fortinet appliance a full month before the US federal catalogue confirmed it . Confirmation is a record of what somebody has seen, not a guarantee of what is happening.
JPCERT/CC issued the alert because the affected products are widely deployed in Japan and Cloud Software Group, which owns NetScaler, offers no workaround, only fixed versions. That leaves an administrator with one option and a change window to book. An alert riding on a public proof of concept can itself shorten the interval before somebody tries it, which is the trade every coordination centre makes when it publishes early.
