/00 — boot sequence

Hello.

Article

Citrix NetScaler CVE-2026-8451: New CitrixBleed Flaw Under Active Attack

July 10, 2026•5 min read
security citrix netscaler cve-2026-8451 vulnerability cybersecurity

Citrix has patched six NetScaler ADC and NetScaler Gateway vulnerabilities, including CVE-2026-8451, a high-severity memory overread flaw that is already being exploited in the wild within 24 hours of disclosure. Security researchers at watchTowr Labs discovered that the vulnerability shares the same root cause as the March 2026 CitrixBleed variant (CVE-2026-3055) and allows attackers to leak sensitive memory contents by sending malformed SAML authentication requests.

Vulnerability Details

CVE-2026-8451 is an insufficient input validation vulnerability in NetScaler's SAML Identity Provider (IdP) parsing code. When NetScaler ADC or NetScaler Gateway is configured as a SAML IdP, an attacker can send a crafted SAML request that triggers an out-of-bounds memory read. The flaw carries a CVSS score of 8.8 (High).

The vulnerability was discovered and reported by Aliz Hammond of watchTowr Labs alongside Michael Tucker from JPMorgan Chase. In a technical write-up, watchTowr noted that while the original CVE-2026-3055 could leak kilobytes of binary data, CVE-2026-8451 terminates the out-of-bounds read when control characters (such as NULL or >) are encountered. In practice, varying the request length consistently leaks a few bytes per attempt, which is enough for attackers to extract sensitive information over repeated probing.

Impact Assessment

The six flaws patched in this cycle include:

CVECVSSTypeDescription
CVE-2026-84518.8Memory OverreadSAML IdP insufficient input validation, leaks memory
CVE-2026-134758.8Memory OverflowDoS via memory overflow in Gateway/AAA virtual server
CVE-2026-134768.8Memory OverflowDoS in LB Oracle, DNS Proxy, DNS recursive resolver
CVE-2026-134778.8Memory OverflowDoS in LB Oracle, DNS Proxy, DNS recursive resolver
CVE-2026-134748.7DoSHTTP/2 small window stalled streams, memory exhaustion
CVE-2026-134787.7File ReadUnauthenticated arbitrary file read via path control

What makes CVE-2026-8451 particularly concerning is the speed of exploitation. Threat intelligence firm Lupovis observed an IP address from Frankfurt (146.70.139.154) targeting its honeypot sensors within 24 hours of public disclosure. The attackers employed sophisticated targeting logic: they first probed sensors with a 200 OK response and only delivered the full exploit payload when the expected response was received. Sensors returning 404 were skipped entirely.

This pattern suggests automated, validated exploitation rather than opportunistic scanning.

Affected Systems

Organizations running any of the following versions must act immediately:

  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-72.61
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-63.18
  • NetScaler ADC 14.1-FIPS before 14.1-72.61 FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1.37.272

Mitigation and Patching

Step 1: Upgrade Immediately

Upgrade to the patched versions listed above. For most organizations, the path is to 14.1-72.61 or later, or 13.1-63.18 or later for the 13.1 track.

Step 2: Configure HTTP/2 Settings (CVE-2026-13474)

For the HTTP/2 denial-of-service vulnerability (CVE-2026-13474), a configuration change is also required. The Http2SmallWndTimeout parameter must be set to 30 seconds:

set ns httpProfile <profile_name> -http2SmallWndTimeout 30

For appliances using HTTP Strict Profiles, this parameter defaults to 30 seconds after the upgrade, and the fix is effective immediately. For appliances NOT using HTTP Strict Profiles, the default value is 0, meaning the upgrade alone does not fully address CVE-2026-13474.

Step 3: Review SAML IdP Configurations

If your NetScaler is configured as a SAML Identity Provider, prioritize this patch. The exploitation vector directly targets SAML IdP functionality, and active exploit code is already circulating.

Detection

Lupovis observed the following indicators of exploitation:

  • Source IP: 146.70.139.154 (Frankfurt, subsequently used in multiple targeting attempts)
  • Attackers first send a probe and validate a 200 OK response before delivering the exploit
  • Payload matches the proof-of-concept released by watchTowr Labs

If you see unusual SAML authentication requests to your NetScaler appliances, investigate immediately. Monitor for out-of-bounds read patterns and unexpected process restarts on affected appliances.

Frequently Asked Questions

Is this the same as the original CitrixBleed (CVE-2023-4966)? No, but it shares the same architectural weakness. Both are memory overread flaws in Citrix NetScaler's parsing logic, but CVE-2026-8451 is specific to SAML IdP processing and is less severe in terms of data leakage volume.

Does this affect Citrix ADC or just NetScaler? NetScaler ADC is the renamed Citrix ADC product line. Both names refer to the same appliances.

Can the file read flaw (CVE-2026-13478) be used to read sensitive files? Yes. CVE-2026-13478 allows unauthenticated arbitrary file reads when access to NSIP, Cluster Management IP, or SNIP with management access is enabled. This could expose configuration files containing credentials.

Do I need to update both ADC and Gateway? Yes. The vulnerabilities affect both NetScaler ADC and NetScaler Gateway products on the affected versions.

Is there evidence of ransomware groups exploiting this? Not yet, but Citrix appliances have been a lucrative target for ransomware deployment in the past. The speed of active exploitation makes patching urgent.

Key Takeaways

  • CVE-2026-8451 is a CVSS 8.8 memory overread in NetScaler SAML IdP, actively exploited within 24 hours
  • Five additional flaws were patched, including a file read (CVSS 7.7) and multiple DoS vectors (CVSS 8.7-8.8)
  • Patched versions: 14.1-72.61+ and 13.1-63.18+ for mainline, 13.1.37.272+ for FIPS/NDcPP
  • CVE-2026-13474 (HTTP/2 DoS) requires a manual configuration parameter change after upgrading
  • Exploitation is targeted and automated, with attackers validating vulnerable targets before delivery

Conclusion

The rapid exploitation of CVE-2026-8451, combined with the six additional flaws in this patch batch, makes this an urgent update for any organization running NetScaler appliances. The pattern of CitrixBleed-like vulnerabilities appearing repeatedly suggests a systemic memory management issue in NetScaler's SAML and HTTP parsing layers. Until a more fundamental fix is available, a rigorous patch discipline is the only defense.


Sources: The Hacker News - Citrix Patches Six NetScaler Flaws, watchTowr Labs Technical Write-up, SecurityWeek, Lupovis Threat Intelligence

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.

Resources & Links