Citrix has patched six NetScaler ADC and NetScaler Gateway vulnerabilities, including CVE-2026-8451, a high-severity memory overread flaw that is already being exploited in the wild within 24 hours of disclosure. Security researchers at watchTowr Labs discovered that the vulnerability shares the same root cause as the March 2026 CitrixBleed variant (CVE-2026-3055) and allows attackers to leak sensitive memory contents by sending malformed SAML authentication requests.
Vulnerability Details
CVE-2026-8451 is an insufficient input validation vulnerability in NetScaler's SAML Identity Provider (IdP) parsing code. When NetScaler ADC or NetScaler Gateway is configured as a SAML IdP, an attacker can send a crafted SAML request that triggers an out-of-bounds memory read. The flaw carries a CVSS score of 8.8 (High).
The vulnerability was discovered and reported by Aliz Hammond of watchTowr Labs alongside Michael Tucker from JPMorgan Chase. In a technical write-up, watchTowr noted that while the original CVE-2026-3055 could leak kilobytes of binary data, CVE-2026-8451 terminates the out-of-bounds read when control characters (such as NULL or >) are encountered. In practice, varying the request length consistently leaks a few bytes per attempt, which is enough for attackers to extract sensitive information over repeated probing.
Impact Assessment
The six flaws patched in this cycle include:
| CVE | CVSS | Type | Description |
|---|---|---|---|
| CVE-2026-8451 | 8.8 | Memory Overread | SAML IdP insufficient input validation, leaks memory |
| CVE-2026-13475 | 8.8 | Memory Overflow | DoS via memory overflow in Gateway/AAA virtual server |
| CVE-2026-13476 | 8.8 | Memory Overflow | DoS in LB Oracle, DNS Proxy, DNS recursive resolver |
| CVE-2026-13477 | 8.8 | Memory Overflow | DoS in LB Oracle, DNS Proxy, DNS recursive resolver |
| CVE-2026-13474 | 8.7 | DoS | HTTP/2 small window stalled streams, memory exhaustion |
| CVE-2026-13478 | 7.7 | File Read | Unauthenticated arbitrary file read via path control |
What makes CVE-2026-8451 particularly concerning is the speed of exploitation. Threat intelligence firm Lupovis observed an IP address from Frankfurt (146.70.139.154) targeting its honeypot sensors within 24 hours of public disclosure. The attackers employed sophisticated targeting logic: they first probed sensors with a 200 OK response and only delivered the full exploit payload when the expected response was received. Sensors returning 404 were skipped entirely.
This pattern suggests automated, validated exploitation rather than opportunistic scanning.
Affected Systems
Organizations running any of the following versions must act immediately:
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-72.61
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-63.18
- NetScaler ADC 14.1-FIPS before 14.1-72.61 FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1.37.272
Mitigation and Patching
Step 1: Upgrade Immediately
Upgrade to the patched versions listed above. For most organizations, the path is to 14.1-72.61 or later, or 13.1-63.18 or later for the 13.1 track.
Step 2: Configure HTTP/2 Settings (CVE-2026-13474)
For the HTTP/2 denial-of-service vulnerability (CVE-2026-13474), a configuration change is also required. The Http2SmallWndTimeout parameter must be set to 30 seconds:
set ns httpProfile <profile_name> -http2SmallWndTimeout 30
For appliances using HTTP Strict Profiles, this parameter defaults to 30 seconds after the upgrade, and the fix is effective immediately. For appliances NOT using HTTP Strict Profiles, the default value is 0, meaning the upgrade alone does not fully address CVE-2026-13474.
Step 3: Review SAML IdP Configurations
If your NetScaler is configured as a SAML Identity Provider, prioritize this patch. The exploitation vector directly targets SAML IdP functionality, and active exploit code is already circulating.
Detection
Lupovis observed the following indicators of exploitation:
- Source IP: 146.70.139.154 (Frankfurt, subsequently used in multiple targeting attempts)
- Attackers first send a probe and validate a 200 OK response before delivering the exploit
- Payload matches the proof-of-concept released by watchTowr Labs
If you see unusual SAML authentication requests to your NetScaler appliances, investigate immediately. Monitor for out-of-bounds read patterns and unexpected process restarts on affected appliances.
Frequently Asked Questions
Is this the same as the original CitrixBleed (CVE-2023-4966)? No, but it shares the same architectural weakness. Both are memory overread flaws in Citrix NetScaler's parsing logic, but CVE-2026-8451 is specific to SAML IdP processing and is less severe in terms of data leakage volume.
Does this affect Citrix ADC or just NetScaler? NetScaler ADC is the renamed Citrix ADC product line. Both names refer to the same appliances.
Can the file read flaw (CVE-2026-13478) be used to read sensitive files? Yes. CVE-2026-13478 allows unauthenticated arbitrary file reads when access to NSIP, Cluster Management IP, or SNIP with management access is enabled. This could expose configuration files containing credentials.
Do I need to update both ADC and Gateway? Yes. The vulnerabilities affect both NetScaler ADC and NetScaler Gateway products on the affected versions.
Is there evidence of ransomware groups exploiting this? Not yet, but Citrix appliances have been a lucrative target for ransomware deployment in the past. The speed of active exploitation makes patching urgent.
Key Takeaways
- CVE-2026-8451 is a CVSS 8.8 memory overread in NetScaler SAML IdP, actively exploited within 24 hours
- Five additional flaws were patched, including a file read (CVSS 7.7) and multiple DoS vectors (CVSS 8.7-8.8)
- Patched versions: 14.1-72.61+ and 13.1-63.18+ for mainline, 13.1.37.272+ for FIPS/NDcPP
- CVE-2026-13474 (HTTP/2 DoS) requires a manual configuration parameter change after upgrading
- Exploitation is targeted and automated, with attackers validating vulnerable targets before delivery
Conclusion
The rapid exploitation of CVE-2026-8451, combined with the six additional flaws in this patch batch, makes this an urgent update for any organization running NetScaler appliances. The pattern of CitrixBleed-like vulnerabilities appearing repeatedly suggests a systemic memory management issue in NetScaler's SAML and HTTP parsing layers. Until a more fundamental fix is available, a rigorous patch discipline is the only defense.
Sources: The Hacker News - Citrix Patches Six NetScaler Flaws, watchTowr Labs Technical Write-up, SecurityWeek, Lupovis Threat Intelligence
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.