logo

Citrix NetScaler Vulnerability CVE-2026-8451 Exploited in the Wild as PoC Goes Public

ID: ed3f6f6b-86f0-5aad-9f25-fa2b51e9adcb

STIX ID: report--ed3f6f6b-86f0-5aad-9f25-fa2b51e9adcb

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-07-02

Date Updated: 2026-08-06

Author: Do Son

...
...

A high-severity pre-auth memory overread (CVE-2026-8451, CVSS 8.8) in Citrix NetScaler/Gateway SAML attribute parsing is being actively exploited in the wild shortly after public PoC release; attackers can trigger leaked process memory via crafted base64 SAML AuthnRequests to /saml/login (no credentials required), potentially exposing sessions and seeding further exploitation. Citrix has released fixed builds (move to 14.1-72.61 or 13.1-63.18+), and defenders are advised to patch immediately and hunt for malformed SAML requests and NSC_TASS cookie anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.