CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public Disclosure
ID: daaf03d6-3463-5cfe-8860-a4900a84eb52
STIX ID: report--daaf03d6-3463-5cfe-8860-a4900a84eb52
Feed Name: cybersecurityNews.com
Active exploitation of CitrixBleed CVE-2026-8451 was observed within 24 hours of disclosure: Lupovis decoys recorded coordinated scanning and a delivered SAML AuthnRequest over-read payload from IP 146.70.139.154 targeting NetScaler ADC/Gateway configured as a SAML IdP (affected 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18). The report details the exploitation technique (unquoted attribute newline causing out-of-bounds read into NSC_TASS), behavioral telemetry showing validation-before-exploit, and provides IOCs (IP, user-agent, endpoint, payload pattern).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
