RESEARCHERS at watchTowr have published an exploit for the Citrix NetScaler RCE vulnerability, CVE-2026-8452, allowing unauthenticated attackers to execute code as root. This vulnerability, rated CVSS 9.8, affects several versions of NetScaler ADC and Gateway and has the potential for severe network impact. The flaw stems from a SAML canonicalization overflow that can corrupt memory and lead to code execution.
Citrix has released patches for affected versions, and users are urged to upgrade immediately, as there have been no confirmed exploitations reported yet, though a proof-of-concept is publicly available.