All incidents

Citrix NetScaler CVE-2026-8451 exploited in the wild

vulnerabilityclosedJun 30, 2026 — Jul 6, 2026
Citrix patches multiple NetScaler ADC and Gateway vulnerabilities

CITRIX has released patches for a cluster of flaws affecting NetScaler ADC and Gateway appliances, the most serious of which is being actively exploited in the wild. The disclosure came on 30 June 2026 and immediately triggered scanning campaigns against exposed devices.

The flagship issue, tracked as CVE‑2026-8451, scores 8.8 on the CVSS scale and stems from an out‑of‑bounds read in the XML parser that allows unauthenticated attackers to trigger a memory overread on SAML identity provider configurations. Successful exploitation can leak sensitive memory contents without requiring any prior authentication.

Affected releases include NetScaler ADC and Gateway 14.1 before build 14.1‑72.61 and 13.1 before build 13.1‑63.18; patched builds were made available shortly after disclosure. Administrators are advised to apply the updates or, as a temporary measure, disable SAML IDP functionality on exposed appliances.

Researchers at Lupovis observed scanning and exploit attempts within hours of the public proof‑of‑concept, echoing the rapid abuse seen during the earlier CitrixBleed incident. While no specific threat actor has been linked to the activity, the volume of probing indicates opportunistic actors are attempting to weaponise the flaw. The speed of abuse underscores the urgency of patching before attackers can harvest credentials or session tokens.

In addition to CVE‑2026-8451, Citrix’s advisory covers five other high‑severity flaws, CVE‑2026-8452, CVE‑2026-8655, CVE‑2026-10816 and the HTTP/2 Bomb tracked as CVE‑2026-13474. Each of these issues requires particular configurations to be exploitable, but all are remedied by the same update bundles. Organizations should prioritize installing the patches for all affected versions to close the entire attack surface.

Defenders should upgrade vulnerable appliances to the patched builds, disable SAML IDP functionality if immediate patching is not feasible, and review appliance logs for anomalous XML parsing errors or unexpected outbound connections. Maintaining an inventory of NetScaler instances and verifying patch levels will help prevent reinfection.

Intelligence briefing updated Jul 6, 2026

CVE-2026-8451 8.8 CVE-2026-8452 8.8 CVE-2026-8655 8.8 CVE-2026-13474 8.7 CVE-2026-10816 7.1
Root sourcelabs.watchtowr.com
Timeline Coverage

Swipe to explore timeline