logo

CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public Disclosure

ID: daaf03d6-3463-5cfe-8860-a4900a84eb52

STIX ID: report--daaf03d6-3463-5cfe-8860-a4900a84eb52

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-07-02

Date Updated: 2026-07-02

Author: Guru Baran

...
...

Active exploitation of CitrixBleed CVE-2026-8451 was observed within 24 hours of disclosure: Lupovis decoys recorded coordinated scanning and a delivered SAML AuthnRequest over-read payload from IP 146.70.139.154 targeting NetScaler ADC/Gateway configured as a SAML IdP (affected 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18). The report details the exploitation technique (unquoted attribute newline causing out-of-bounds read into NSC_TASS), behavioral telemetry showing validation-before-exploit, and provides IOCs (IP, user-agent, endpoint, payload pattern).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.