CVE-2026-8451
Citrix ADC VPX vulnerability analysis and mitigation

Overview

CVE-2026-8451 is a memory overread vulnerability (dubbed "CitrixBleed-class") in Citrix NetScaler ADC and NetScaler Gateway that allows unauthenticated remote attackers to read sensitive data from memory when the appliance is configured as a SAML Identity Provider (IDP). The vulnerability was disclosed on June 30, 2026, with patches released the same day. Affected versions include NetScaler ADC and Gateway 13.1 before 63.18, 14.1 before 72.61, NetScaler ADC 13.1 FIPS/NDcPP before 37.272, and NetScaler ADC 14.1 FIPS before 72.61. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.8 (High) (GitHub Advisory, Citrix Advisory).

Technical details

The root cause is insufficient input validation in the SAML IDP processing code path, classified as CWE-125 (Out-of-bounds Read). When a NetScaler appliance is configured as a SAML IDP, a specially crafted SAML AuthnRequest can trigger the appliance to read memory beyond the intended buffer boundary, potentially exposing sensitive in-memory data. The attack requires no authentication, no user interaction, and no special privileges — only that the target appliance has the SAML IDP role enabled. WatchTowr Labs published a detailed technical write-up titled "CitrixBleed to Infinity and Beyond" describing the mechanics, noting that as few as 476 spaces and a partially formed XML tag in a SAML request are sufficient to trigger the overread (WatchTowr Labs).

Impact

Successful exploitation allows an unauthenticated attacker to disclose sensitive data from the appliance's memory, which may include session tokens, credentials, cryptographic material, or other confidential information processed by the NetScaler device. Given that NetScaler ADC and Gateway are commonly deployed as enterprise network access and authentication chokepoints, memory disclosure could enable session hijacking, credential theft, and lateral movement into protected internal networks. The CVSS v4.0 scoring also reflects a high availability impact on the vulnerable system, suggesting the overread condition can also destabilize the appliance (GitHub Advisory, eSentire Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing NetScaler ADC or Gateway appliances using tools like Shodan or Censys, filtering for versions 13.1 < 63.18 or 14.1 < 72.61. Confirm SAML IDP configuration is active by probing SAML-related endpoints (e.g., /saml/login).
  2. Craft malicious SAML AuthnRequest: Construct a specially crafted SAML AuthnRequest XML payload containing approximately 476 or more spaces and/or a partially formed XML tag designed to trigger the out-of-bounds read in the SAML IDP parsing code.
  3. Send unauthenticated HTTP request: Submit the malicious SAML AuthnRequest to the target appliance's SAML IDP endpoint without any authentication credentials or session tokens.
  4. Capture memory disclosure: Parse the server's response for leaked memory contents, which may include session tokens, authentication credentials, cryptographic keys, or other sensitive data resident in the appliance's memory at the time of the request.
  5. Leverage disclosed data: Use any captured session tokens to hijack active user sessions, or use disclosed credentials to authenticate to internal resources, enabling lateral movement into the enterprise network (WatchTowr Labs, eSentire Advisory).

Indicators of compromise

  • Network: Unusual or high-volume unauthenticated POST/GET requests to SAML IDP endpoints (e.g., /saml/login, /saml/idp) from external IP addresses; responses to SAML requests containing anomalously large or malformed data payloads; outbound connections from the NetScaler appliance to unknown external IPs.
  • Logs: NetScaler access logs showing repeated SAML AuthnRequest submissions from single or rotating IP addresses with oversized or malformed XML payloads; error log entries related to memory or buffer handling in SAML processing components; authentication events using session tokens not associated with a prior login flow.
  • File System: Unexpected configuration changes to ns.conf (detectable via the public netscaler_cve_checker.py tool); new or modified files in NetScaler web directories.
  • Behavioral: Sudden appearance of authenticated sessions without corresponding login events in audit logs; session tokens being reused from IP addresses inconsistent with the original authenticating user's location (CrowdSec Report, eSentire Advisory).

Mitigation and workarounds

Citrix released patches on June 30, 2026. Organizations should upgrade to the following fixed versions immediately: NetScaler ADC and Gateway 14.1-72.61 or later; NetScaler ADC and Gateway 13.1-63.18 or later; NetScaler ADC 13.1 FIPS and NDcPP 13.1-37.272 or later; NetScaler ADC 14.1 FIPS 14.1-72.61 or later. As a configuration-based workaround, disable the SAML IDP role on any appliance where it is not strictly required, as the vulnerability is only exploitable when the appliance is configured as a SAML IDP. Organizations should also monitor SAML IDP endpoints for anomalous traffic and review active sessions for signs of token hijacking (Citrix Advisory, GitHub Advisory).

Community reactions

The vulnerability drew immediate and widespread attention from the security community due to its similarity to the original CitrixBleed (CVE-2023-4966), with researchers and media outlets widely adopting the "CitrixBleed-class" label. WatchTowr Labs published a detailed technical analysis within hours of disclosure, which rapidly circulated on Reddit (r/netsec, r/cybersecurity, r/blueteamsec) and Mastodon (WatchTowr Labs). Security researcher Kevin Gosselin (@GossiTheDog) and others on Mastodon highlighted the rapid exploitation timeline. Multiple national CERTs issued advisories within 24–72 hours, including Canada's CCCS, Hong Kong's HKCERT, Singapore's CSA, and the UK's NHS Digital (Canadian CCCS, HKCERT). The Stack Technology noted that Citrix credited JPMorgan in the advisory, suggesting coordinated disclosure with a major financial institution.

Additional resources


SourceThis report was generated using AI

Related Citrix ADC VPX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8655HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-8452HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-8451HIGH8.8
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-13474HIGH8.7
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026
CVE-2026-10817MEDIUM6.9
  • Citrix ADC VPX logoCitrix ADC VPX
  • cpe:2.3:a:citrix:netscaler_application_delivery_controller
NoYesJun 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management