Citrix NetScaler Vulnerability CVE-2026-8451 Exploited in the Wild as PoC Goes Public
ID: ed3f6f6b-86f0-5aad-9f25-fa2b51e9adcb
STIX ID: report--ed3f6f6b-86f0-5aad-9f25-fa2b51e9adcb
Feed Name: securityonline.info
A high-severity pre-auth memory overread (CVE-2026-8451, CVSS 8.8) in Citrix NetScaler/Gateway SAML attribute parsing is being actively exploited in the wild shortly after public PoC release; attackers can trigger leaked process memory via crafted base64 SAML AuthnRequests to /saml/login (no credentials required), potentially exposing sessions and seeding further exploitation. Citrix has released fixed builds (move to 14.1-72.61 or 13.1-63.18+), and defenders are advised to patch immediately and hunt for malformed SAML requests and NSC_TASS cookie anomalies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
