CVE Tools

New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure

SecurityWeekBy Ionut Arghire

Reported exploitedCitrix NetScaler ADCCitrix NetScaler Gateway

Our summary

Threat actors reportedly started attacking affected Citrix NetScaler ADC and NetScaler Gateways almost immediately after public disclosure, with exploitation observed in under 24 hours. The issue, tracked as CVE-2026-8451 (CVSS 8.8), is an out-of-bounds read in the NetScaler XML parser that can disclose memory contents via the NSC_TASS cookie when appliances are configured as SAML IDP; no authentication is required for successful exploitation. This matters because the rapid weaponization suggests exposed internet-facing systems could be targeted quickly, so organizations should prioritize patching or mitigate by disabling SAML IDP and checking relevant logs and cookies.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store