CitrixBleed-ing Again? NetScaler Vulnerability Under Attack

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A new memory overread vulnerability in Citrix NetScaler (CVE-2026-8451), affecting ADC and Gateway devices configured as SAML identity providers, is under active exploitation. Discovered by WatchTowr and disclosed on June 30, the flaw received a CVSS score of 8.8. Within 24 hours of WatchTowr publishing a proof-of-concept exploit, cybersecurity vendor Lupovis detected a coordinated scanning campaign using the exact PoC payload. The vulnerability is reminiscent of the infamous CitrixBleed (CVE-2023-4966) and can allow attackers to leak sensitive memory contents, escalate privileges, move laterally, and exfiltrate data. Organizations are urged to patch immediately to versions 14.1-72.61 or 13.1-63.18, disable SAML IDP if patching is not possible, and review SAML login activity from June 30 onward.

4m read timeFrom darkreading.com
Post cover image
Table of contents
Another NetScaler Flaw Under Attack?Corporate Risks Posed by CVE-2026-8451
64 Impressions