CVE Tools

CitrixBleed-ing Again? NetScaler Vulnerability Under Attack

Dark ReadingBy Rob Wright

Reported exploitedNetScaler Application Delivery ControllerNetScaler Gateway

Our summary

Citrix disclosed CVE-2026-8451, a memory overread issue in NetScaler ADC and NetScaler Gateway devices configured as a SAML identity provider (IDP), with a CVSS score of 8.8. Researchers and security vendors report that threat actors are actively scanning for and using a proof-of-concept-style exploit, potentially leaking sensitive information and enabling further compromise (including privilege escalation and lateral movement). Organizations using affected NetScaler systems should prioritize applying the fixed versions and reviewing SAML IDP activity for suspicious events.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store