CitrixBleed-ing Again? NetScaler Vulnerability Under Attack
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A new memory overread vulnerability in Citrix NetScaler (CVE-2026-8451), affecting ADC and Gateway devices configured as SAML identity providers, is under active exploitation. Discovered by WatchTowr and disclosed on June 30, the flaw received a CVSS score of 8.8. Within 24 hours of WatchTowr publishing a proof-of-concept exploit, cybersecurity vendor Lupovis detected a coordinated scanning campaign using the exact PoC payload. The vulnerability is reminiscent of the infamous CitrixBleed (CVE-2023-4966) and can allow attackers to leak sensitive memory contents, escalate privileges, move laterally, and exfiltrate data. Organizations are urged to patch immediately to versions 14.1-72.61 or 13.1-63.18, disable SAML IDP if patching is not possible, and review SAML login activity from June 30 onward.