Citrix has patched CVE-2026-8451, a memory overread vulnerability in NetScaler ADC and Gateway appliances acting as SAML identity providers. Discovered by watchTowr Labs, the flaw stems from a custom in-house XML parser that fails to properly bound-check unquoted attribute values in SAML AuthnRequests, allowing an unauthenticated attacker to leak raw process memory via the NSC_TASS response cookie. A secondary payload can crash the nsppe process entirely. The bug echoes the 2023 CitrixBleed (CVE-2023-4966) disaster, sharing the same root cause of fragile memory management in untrusted input parsing. Citrix was notified in March 2026 and shipped fixes on June 30 alongside five other CVEs. No active exploitation has been confirmed yet, but NetScaler's history of rapid weaponization makes urgent patching critical. Admins unable to patch immediately should disable SAML IdP functionality and restrict access to the /saml/login endpoint.