CVE-2026-8451
published 2026-06-30CVE-2026-8451: Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML…
PriorityP278high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
15.65%
96.6th percentile
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_application_delivery_controller | < 13.1-37.272 | 13.1-37.272 |
| citrix | netscaler_application_delivery_controller | — | — |
| citrix | netscaler_application_delivery_controller | >= 13.1 < 13.1-63.18 | 13.1-63.18 |
| citrix | netscaler_application_delivery_controller | >= 14.1 < 14.1-72.61 | 14.1-72.61 |
| citrix | netscaler_gateway | — | — |
| citrix | netscaler_gateway | >= 13.1 < 13.1-63.18 | 13.1-63.18 |
| citrix | netscaler_gateway | >= 14.1 < 14.1-72.61 | 14.1-72.61 |
| citrix | xenserver | — | — |
| netscaler | adc | >= 13.1 < 63.18 | 63.18 |
| netscaler | adc | >= 13.1 FIPS and NDcPP < 37.272 | 37.272 |
| netscaler | adc | >= 14.1 < 72.61 | 72.61 |
| netscaler | adc | >= 14.1 FIPs < 72.61 | 72.61 |
| netscaler | gateway | >= 13.1 < 63.18 | 63.18 |
| netscaler | gateway | >= 14.1 < 72.61 | 72.61 |
Detection & IOCsextracted from sources · hover to see the quote
- →Check Point IPS signature available for detection of CVE-2026-8451 exploitation attempts against NetScaler ADC/Gateway SAML IDP configurations ↗
- →Active exploitation observed within 24 hours of disclosure; attacks target SAML Identity Provider configurations to leak session tokens — prioritize detection on appliances configured as SAML IDP ↗
- ·Vulnerability is only exploitable when NetScaler ADC or NetScaler Gateway is configured as a SAML Identity Provider (IDP); appliances not in this role are not affected ↗
- ·Multiple Citrix products are covered under the same security bulletin; ensure patching scope includes all listed affected products ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Citrix NetScaler ADC/NetScaler Gateway buffer overflow (CTX696604)
vuldb·2026-06-30·CVSS 8.8
CVE-2026-8451 [HIGH] Citrix NetScaler ADC/NetScaler Gateway buffer overflow (CTX696604)
A vulnerability, which was classified as critical, has been found in Citrix NetScaler ADC and NetScaler Gateway. The impacted element is an unknown function. Performing a manipulation results in buffer overflow.
This vulnerability is known as CVE-2026-8451. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
ghsa_unreviewed·2026-06-30
CVE-2026-8451 [HIGH] CWE-125 Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
VulnCheck
Citrix NetScaler ADC and NetScaler Gateway Out-of-bounds Read
vulncheck·2026·CVSS 7.5
CVE-2026-8451 [HIGH] Citrix NetScaler ADC and NetScaler Gateway Out-of-bounds Read
Citrix NetScaler ADC and NetScaler Gateway Out-of-bounds Read
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
Affected: Citrix NetScaler ADC and NetScaler Gateway
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.lupovis.io/lupovis-insights/; https://kevintel.com/CVE-2026-8451
Exploit PoC: https://vulncheck.com/xdb/c8884e9be221
Citrix
Citrix Security Bulletin CTX696604
vendor_citrix·CVSS 8.8
CVE-2025-5349 [HIGH] Citrix Security Bulletin CTX696604
Citrix Security Bulletin CTX696604
CVE References: CVE-2025-5349, CVE-2025-5777, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397, CVE-2026-8451, CVE-2026-8452, CVE-2026-8655
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX696734
vendor_citrix·CVSS 7.5
CVE-2026-10816 [HIGH] Citrix Security Bulletin CTX696734
Citrix Security Bulletin CTX696734
CVE References: CVE-2026-10816, CVE-2026-10817, CVE-2026-13474, CVE-2026-3055, CVE-2026-42491, CVE-2026-4368, CVE-2026-53565, CVE-2026-53566, CVE-2026-8451, CVE-2026-8452, CVE-2026-8655
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Hackernews
Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
blogs_hackernews·2026-08-20·CVSS 8.8
CVE-2026-19489 [HIGH] Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability.
According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess ZTNA Hybrid deployments that use customer-managed NetScaler instances.
It bears noting that the vulnerabilities do not apply to Citrix-managed cloud servi
Checkpoint
6th July – Threat Intelligence Report
blogs_checkpoint·2026-07-06
CVE-2026-46817 6th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 6th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
River Bank & Trust, a US financial institution, has experienced a ransomware incident after an unauthorized actor accessed the network of parent company River Financial Corporation on June 16. The bank found ransomware on portions of its server environment and is assessing whether personal data was accessed or exfiltrated.
Indra
Hackernews
Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
blogs_hackernews·2026-07-01·CVSS 7.1
CVE-2026-8451 [HIGH] Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
Citrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition.
The vulnerabilities are listed below -
CVE-2026-8451 (CVSS score: 8.8) - An insufficient input validation vulnerability leading to memory overread when NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
CVE-2026-8452 (CVSS score: 8.8) - A memory overflow vulnerab
2026-06-30
Published
Exploited in the wild