CVE Tools

CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)

watchTowr LabsBy Aliz Hammond

ResearchNetScaler ADCNetScaler Gateway

Our summary

watchTowr Labs reports that Citrix has publicly disclosed a pre-auth memory disclosure issue, CVE-2026-8451, in Citrix NetScaler when the NetScaler appliance is configured as a SAML IDP. The vulnerability is described as insufficient input validation leading to memory overread, with affected products including NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-72.61, NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.18, NetScaler ADC FIPS BEFORE 14.1-72.61 FIPS, and NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.272. This matters because it can cause the appliance to include unintended memory contents in responses (e.g., within cookies), potentially exposing sensitive data to an unauthenticated attacker.

Read at watchTowr Labs

watchTowr Labs publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store