Citrix has patched CVE-2026-8451, a memory overread vulnerability in NetScaler ADC and Gateway appliances acting as SAML identity providers. Discovered by watchTowr Labs, the flaw stems from a custom in-house XML parser that fails to properly bound-check unquoted attribute values in SAML AuthnRequests, allowing an unauthenticated attacker to leak raw process memory via the NSC_TASS response cookie. A secondary payload can crash the nsppe process entirely. The bug echoes the 2023 CitrixBleed (CVE-2023-4966) disaster, sharing the same root cause of fragile memory management in untrusted input parsing. Citrix was notified in March 2026 and shipped fixes on June 30 alongside five other CVEs. No active exploitation has been confirmed yet, but NetScaler's history of rapid weaponization makes urgent patching critical. Admins unable to patch immediately should disable SAML IdP functionality and restrict access to the /saml/login endpoint.

5m read timeFrom latesthackingnews.com
Post cover image
Table of contents
The NetScaler memory overread bug, explainedWhy this feels like CitrixBleed all over againHow long Citrix sat on the fixA crowded bulletin, and an unusual name on itWhat NetScaler admins should do now
64 Impressions