CVE Tools

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))

watchTowr LabsBy Sina Kheirkhah (@SinSinology)

PoC publicCitrix NetScaler ADCwatchTowr LabsCitrix NetScaler Gateway

Our summary

watchTowr Labs has published a proof-of-concept exploit for a pre-authentication remote code execution vulnerability in Citrix NetScaler ADC and NetScaler Gateway, identified as CVE-2026-8452. The flaw is a heap overflow triggered during the canonicalization of SAML signature data, specifically when processing an overly large PrefixList element within the SignedInfo block. Successful exploitation allows attackers to gain root-level code execution on affected appliances, which are widely used for enterprise remote access. Citrix addressed the issue in recent security bulletins; administrators must update NetScaler ADC and Gateway to version 14.1-72.61 or 13.1-63.18 immediately.

Read at watchTowr Labs

watchTowr Labs publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store