Citrix released fixes for six vulnerabilities in NetScaler ADC and NetScaler Gateway, including CVE-2026-8451, a high-severity out-of-bounds read flaw that can leak sensitive memory from appliances configured as a SAML Identity Provider. The bug affects customer-managed NetScaler ADC, Gateway, and related FIPS/NDcPP variants, and can expose memory contents in the NSC_TASS cookie via malformed requests to the /saml/login endpoint. Other patched issues include CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474, covering risks such as arbitrary file reads, memory corruption, and denial of service, including a new HTTP/2 Bomb attack.
Security researchers and defenders reported that CVE-2026-8451 was exploited in the wild less than 24 hours after public disclosure, with Lupovis observing threat actors scanning exposed NetScaler systems and sending exploit payloads immediately after receiving valid 200 OK responses. The observed activity matched public technical details released by watchTowr, using malformed SAML AuthnRequest data padded to trigger the overread condition. Government and industry advisories urged organizations to patch immediately, disable SAML IdP where patching is not possible, review /saml/login traffic and NSC_TASS cookie values for signs of compromise, restrict management exposure, and follow Citrix incident guidance if exploitation is suspected.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Less than 24 hours after public disclosure, Lupovis observed at least two threat actors probing exposed NetScaler instances and sending exploit payloads to systems that returned valid HTTP 200 responses. The observed payloads matched the watchTowr artefact pattern, indicating immediate in-the-wild exploitation of the CitrixBleed-like flaw.
On July 2, 2026, the Canadian Centre for Cyber Security issued Alert AL26-016 warning about CVE-2026-8451 in customer-managed Citrix NetScaler appliances. The alert urged organizations to patch immediately, follow Citrix compromise guidance if exploitation is suspected, and prioritize hardening and isolation of web-facing applications.
On June 30, 2026, watchTowr published technical details and a detection artefact generator/proof-of-concept for CVE-2026-8451 after reproducing the flaw. The material showed how malformed SAML AuthnRequest input could trigger an out-of-bounds read and leak memory in the NSC_TASS cookie.
On June 30, 2026, Citrix disclosed six vulnerabilities affecting NetScaler ADC, NetScaler Gateway, and related FIPS/NDcPP variants, including CVE-2026-8451, and released security updates for affected supported versions. The issues included memory disclosure, arbitrary file read, memory corruption, and denial-of-service risks, with Citrix-managed cloud services already updated.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcehkcert.org
Open sourcecyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourcesecurityweek.com
Open sourcethreataft.com
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.