You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))
PoC publicCitrix NetScaler ADCwatchTowr LabsCitrix NetScaler GatewayOur summary
watchTowr Labs has published a proof-of-concept exploit for a pre-authentication remote code execution vulnerability in Citrix NetScaler ADC and NetScaler Gateway, identified as CVE-2026-8452. The flaw is a heap overflow triggered during the canonicalization of SAML signature data, specifically when processing an overly large PrefixList element within the SignedInfo block. Successful exploitation allows attackers to gain root-level code execution on affected appliances, which are widely used for enterprise remote access. Citrix addressed the issue in recent security bulletins; administrators must update NetScaler ADC and Gateway to version 14.1-72.61 or 13.1-63.18 immediately.
watchTowr Labs publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.