cbcvebase.
CVE-2026-8451
published 2026-06-30

CVE-2026-8451: Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML…

PriorityP278high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
15.65%
96.6th percentile
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP

Affected

19 ranges
VendorProductVersion rangeFixed in
citrixcitrix_adm
citrixcitrix_hypervisor
citrixcitrix_virtual_apps_and_desktops
citrixendpoint_management
citrixnetscaler_adc
citrixnetscaler_application_delivery_controller< 13.1-37.27213.1-37.272
citrixnetscaler_application_delivery_controller
citrixnetscaler_application_delivery_controller>= 13.1 < 13.1-63.1813.1-63.18
citrixnetscaler_application_delivery_controller>= 14.1 < 14.1-72.6114.1-72.61
citrixnetscaler_gateway
citrixnetscaler_gateway>= 13.1 < 13.1-63.1813.1-63.18
citrixnetscaler_gateway>= 14.1 < 14.1-72.6114.1-72.61
citrixxenserver
netscaleradc>= 13.1 < 63.1863.18
netscaleradc>= 13.1 FIPS and NDcPP < 37.27237.272
netscaleradc>= 14.1 < 72.6172.61
netscaleradc>= 14.1 FIPs < 72.6172.61
netscalergateway>= 13.1 < 63.1863.18
netscalergateway>= 14.1 < 72.6172.61

Detection & IOCsextracted from sources · hover to see the quote

  • Check Point IPS signature available for detection of CVE-2026-8451 exploitation attempts against NetScaler ADC/Gateway SAML IDP configurations
  • Active exploitation observed within 24 hours of disclosure; attacks target SAML Identity Provider configurations to leak session tokens — prioritize detection on appliances configured as SAML IDP
  • ·Vulnerability is only exploitable when NetScaler ADC or NetScaler Gateway is configured as a SAML Identity Provider (IDP); appliances not in this role are not affected
  • ·Multiple Citrix products are covered under the same security bulletin; ensure patching scope includes all listed affected products

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.