
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-8451 is a memory overread vulnerability (dubbed "CitrixBleed-class") in Citrix NetScaler ADC and NetScaler Gateway that allows unauthenticated remote attackers to read sensitive data from memory when the appliance is configured as a SAML Identity Provider (IDP). The vulnerability was disclosed on June 30, 2026, with patches released the same day. Affected versions include NetScaler ADC and Gateway 13.1 before 63.18, 14.1 before 72.61, NetScaler ADC 13.1 FIPS/NDcPP before 37.272, and NetScaler ADC 14.1 FIPS before 72.61. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.8 (High) (GitHub Advisory, Citrix Advisory).
The root cause is insufficient input validation in the SAML IDP processing code path, classified as CWE-125 (Out-of-bounds Read). When a NetScaler appliance is configured as a SAML IDP, a specially crafted SAML AuthnRequest can trigger the appliance to read memory beyond the intended buffer boundary, potentially exposing sensitive in-memory data. The attack requires no authentication, no user interaction, and no special privileges — only that the target appliance has the SAML IDP role enabled. WatchTowr Labs published a detailed technical write-up titled "CitrixBleed to Infinity and Beyond" describing the mechanics, noting that as few as 476 spaces and a partially formed XML tag in a SAML request are sufficient to trigger the overread (WatchTowr Labs).
Successful exploitation allows an unauthenticated attacker to disclose sensitive data from the appliance's memory, which may include session tokens, credentials, cryptographic material, or other confidential information processed by the NetScaler device. Given that NetScaler ADC and Gateway are commonly deployed as enterprise network access and authentication chokepoints, memory disclosure could enable session hijacking, credential theft, and lateral movement into protected internal networks. The CVSS v4.0 scoring also reflects a high availability impact on the vulnerable system, suggesting the overread condition can also destabilize the appliance (GitHub Advisory, eSentire Advisory).
/saml/login)./saml/login, /saml/idp) from external IP addresses; responses to SAML requests containing anomalously large or malformed data payloads; outbound connections from the NetScaler appliance to unknown external IPs.ns.conf (detectable via the public netscaler_cve_checker.py tool); new or modified files in NetScaler web directories.Citrix released patches on June 30, 2026. Organizations should upgrade to the following fixed versions immediately: NetScaler ADC and Gateway 14.1-72.61 or later; NetScaler ADC and Gateway 13.1-63.18 or later; NetScaler ADC 13.1 FIPS and NDcPP 13.1-37.272 or later; NetScaler ADC 14.1 FIPS 14.1-72.61 or later. As a configuration-based workaround, disable the SAML IDP role on any appliance where it is not strictly required, as the vulnerability is only exploitable when the appliance is configured as a SAML IDP. Organizations should also monitor SAML IDP endpoints for anomalous traffic and review active sessions for signs of token hijacking (Citrix Advisory, GitHub Advisory).
The vulnerability drew immediate and widespread attention from the security community due to its similarity to the original CitrixBleed (CVE-2023-4966), with researchers and media outlets widely adopting the "CitrixBleed-class" label. WatchTowr Labs published a detailed technical analysis within hours of disclosure, which rapidly circulated on Reddit (r/netsec, r/cybersecurity, r/blueteamsec) and Mastodon (WatchTowr Labs). Security researcher Kevin Gosselin (@GossiTheDog) and others on Mastodon highlighted the rapid exploitation timeline. Multiple national CERTs issued advisories within 24–72 hours, including Canada's CCCS, Hong Kong's HKCERT, Singapore's CSA, and the UK's NHS Digital (Canadian CCCS, HKCERT). The Stack Technology noted that Citrix credited JPMorgan in the advisory, suggesting coordinated disclosure with a major financial institution.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."