CVE-2026-8451, Citrix NetScaler ADC/Gateway: pre-auth SAML memory overread (CitrixBleed lineage), public PoC
Defender actions
- Inventory and patch internet-facing NetScaler ADC/Gateway to 14.1-72.61 / 13.1-63.18 (or FIPS equivalents) per CTX696604; a public susceptibility-testing tool exists for CVE-2026-8451 and CitrixBleed-lineage siblings have been exploited within days. Where SAML IdP is not required, disable it; audit whether TCP TimeStamp is enabled on LB/CS/VPN vservers (CVE-2026-10817 prerequisite). Hunt NetScaler SAML
/saml/logintraffic for malformed/unterminated XML attributes and oversizedNSC_TASScookies. - Verify (do not assume) that every NetScaler ADC and Gateway is actually running 14.1-72.61 or 13.1-63.18 or later, and 13.1-37.272 or later on any FIPS or NDcPP appliance, whose fixed build differs from the mainline one, and treat any instance whose upgrade was deferred because CVE-2026-8452 read as an availability-only issue as an outstanding pre-auth remote-code-execution exposure rather than an availability risk.
- For any appliance that was internet-reachable as a SAML Identity Provider while unpatched, run a compromise assessment rather than an upgrade alone, the sibling flaw CVE-2026-8451 leaks process memory into the response cookie and has been carried as actively exploited with a public proof of concept since 3 July, so session material and secrets resident in that memory should be treated as disclosed and rotated.
Analysis
Citrix's 2026-06-30 bulletin CTX696604 fixes six NetScaler ADC/Gateway CVEs. The headline flaw, CVE-2026-8451 (CVSS 8.8), is a pre-authentication out-of-bounds read reported by watchTowr Labs in the hand-rolled XML attribute parser behind the /saml/login endpoint, reachable only when the appliance is configured as a SAML Identity Provider (watchTowr Labs, 2026-06-30). The parser terminates unquoted attribute values only on NUL, > or a matching quote (not on whitespace/newline) so an unterminated attribute in a crafted SAML AuthnRequest walks the parser past the buffer boundary; the over-read bytes are returned to the unauthenticated client inside the NSC_TASS response cookie, leaking adjacent process memory one request at a time. This is the fourth CitrixBleed-class memory-safety defect in NetScaler's auth code paths that watchTowr has documented (after CVE-2025-5777, CVE-2025-12101 and the March-2026 CVE-2026-3055); watchTowr released a "Detection Artefact Generator" on GitHub that produces the malformed request so operators can test their own exposure, and no in-the-wild exploitation of CVE-2026-8451 was confirmed at disclosure (watchTowr Labs, 2026-06-30 · CyberScoop, 2026-06-30). The companion CVEs span additional memory overread with TCP TimeStamp enabled (CVE-2026-10817), DoS/undefined-control-flow memory-management issues in Gateway/DNS-proxy/AAA vserver configs (CVE-2026-8452, CVE-2026-8655), an unauthenticated arbitrary file read in the Management Interface (CVE-2026-10816), and CVE-2026-13474. Affected: 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18 (plus FIPS builds); patches are available. NCSC-NL issued advisory NCSC-2026-0216 (NCSC-NL, 2026-06-30).
Cited evidence
However, we believe this is CVE-2026-8452 given its description as a “Memory Overflow” vulnerability.
the vulnerability we’re discussing today is reachable when the Netscaler appliance is configured to use SAML as either a Service Provider (SP) or an Identity Provider (IdP).
During signature canonicalization, earlier versions of the NetScaler solution copy attacker-controlled data from the SAML message's ds:SignedInfo element into a fixed-size global buffer, without checking whether it actually fits.
So we now have a memcpy copying from our packet to any address we want, which is a write-what-where primitive.
nsppe already runs as root, so our shellcode executes as root too.
Actively Exploited, Proof of Concept Available
A new technical analysis, likely related to CVE-2026-8452, was published by Watchtowr
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
Updates2
The original entry covered Citrix's six-CVE NetScaler bulletin and its headline flaw CVE-2026-8451, a pre-authentication memory overread in the SAML /saml/login parser, and described the companion CVE-2026-8452 as a denial-of-service and undefined-control-flow memory-management issue in Gateway and AAA vserver configurations. That description was faithful to the vendor's CVE record and is now known to be a serious understatement. Two deltas follow, and the second is a correction to this pipeline's own record.
The bug published as a memory-overflow issue is a pre-authentication root shell. watchTowr identifies its target from the public record's own wording, writing that "we believe this is CVE-2026-8452 given its description as a “Memory Overflow” vulnerability", the same sparse framing behind the denial-of-service characterisation this pipeline carried on 1 July from Citrix's bulletin. On 2026-08-14 watchTowr Labs published a chain that ends in a root command shell, entirely pre-authentication (watchTowr Labs, 2026-08-14). The identifier is an inference rather than a confirmation, watchTowr says so plainly, and Switzerland's NCSC describes the work as "A new technical analysis, likely related to CVE-2026-8452, was published by Watchtowr" (NCSC-CH, 2026-08-14), but the bug watchTowr analysed is fixed by the same release, so the operational conclusion does not depend on resolving the mapping.
The kill chain. The defect is in SAML signature canonicalization: "During signature canonicalization, earlier versions of the NetScaler solution copy attacker-controlled data from the SAML message's ds:SignedInfo element into a fixed-size global buffer, without checking whether it actually fits" (watchTowr Labs, 2026-08-14). The attacker-controlled field is the PrefixList attribute of the InclusiveNamespaces element inside the ds:SignedInfo block, and the copy target sits in nsppe, NetScaler's packet-processing engine. An oversized value overflows linearly into the header of the adjacent chunk in the appliance's network-buffer pool, corrupting that neighbour's data-pointer and freelist-link fields. The corruption becomes an attacker primitive later, when the packet engine retrieves that chunk and performs a memcpy using the corrupted pointer as its destination with an attacker-influenced length: "So we now have a memcpy copying from our packet to any address we want, which is a write-what-where primitive." From there the exploit is unusually cheap, because the target offers almost no mitigations ("The nsppe binary lacks almost all of the protections you'd hope to find, and the heap is executable, for reasons known only to Citrix") so watchTowr redirected execution into shellcode placed on a heap that is both executable and at a fixed address, and "nsppe already runs as root, so our shellcode executes as root too."
Two engineering details in the chain matter to defenders more than the memory corruption does. First, an nsppe crash normally triggers a full appliance reboot through a watchdog process, which would destroy anything the attacker dropped; watchTowr neutralised the packet engine's crash-signal handlers so the watchdog merely respawned the process instead of rebooting the box, letting a dropped PHP webshell survive. Second, because the web server executing that webshell runs as an unprivileged account while nsppe runs as root, the exploit set the SUID bit on /bin/sh from the root shellcode so that commands issued through the webshell execute with a root effective UID (watchTowr Labs, 2026-08-14). The result is durable root that survives the process restart an operator would most likely dismiss as a glitch.
Reachability. watchTowr states the vulnerability "is reachable when the Netscaler appliance is configured to use SAML as either a Service Provider (SP) or an Identity Provider (IdP)" (watchTowr Labs, 2026-08-14), which, in the deployment terms Citrix's bulletin used and this pipeline recorded on 1 July, is any appliance acting as a Gateway or AAA virtual server. That is the ordinary shape of a remote-access appliance in a European government or critical-infrastructure network, and it is broader than the sibling flaw's precondition: NCSC-CH records that one as requiring the appliance to be configured as a SAML Identity Provider specifically (NCSC-CH, advisory of 2026-07-03). Affected are NetScaler ADC and Gateway 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18, and both CVE records additionally list the FIPS and NDcPP builds, 14.1 FIPS before 14.1-72.61 and 13.1 FIPS/NDcPP before 13.1-37.272, a different fixed build that an estate running certified appliances has to check for separately. Both flaws were fixed together in that June/July release. No party reports in-the-wild exploitation of the code-execution chain.
The correction. The original entry recorded that no in-the-wild exploitation of CVE-2026-8451 was confirmed at disclosure. NCSC-CH's advisory on that flaw, timestamped 2026-07-03, states its current exploitation status as "Actively Exploited, Proof of Concept Available", and cites reporting that it was exploited immediately after public disclosure (NCSC-CH, advisory of 2026-07-03, updated 2026-08-14). That status has stood since early July and this pipeline did not carry it, so an estate that read the 1 July entry and concluded the memory-overread flaw was unexploited was working from a stale picture for six weeks. The exploitation is not new; the record here was wrong.
Triage: the distinctive telemetry is a crash that does not behave like a NetScaler crash. In appliance system and error logs, an nsppe process restart without the full appliance reboot that normally follows one is the signature this exploit deliberately produces, and it is worth correlating against inbound SAML authentication attempts in the same interval. On the request side, SAML AuthnRequest and Response bodies carrying an anomalously large InclusiveNamespaces PrefixList attribute inside a SignedInfo block are the delivery shape; legitimate SAML messages carry short namespace-prefix lists, so length is a usable discriminator here rather than a heuristic. Where any host-level telemetry is available from the appliance, a shell process spawned by the web server is decisive: a NetScaler web server has no legitimate reason to spawn a shell, and the SUID step means the shell will carry a root effective UID under a process that should never have one.
CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog on 2026-08-26: "Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service" (CISA Known Exploited Vulnerabilities Catalog, 2026-08-26). This is the first authoritative confirmation that CVE-2026-8452 specifically is under active exploitation, closing the gap the prior update left open when watchTowr said only that it "believes but cannot confirm" its pre-authentication root-shell chain maps to this identifier, and NCSC-CH called the analysis merely "likely related." The KEV addition does not itself confirm which exploitation activity is occurring (CISA's own description still reads as a memory-safety/denial-of-service issue, the same sparse framing that understated the flaw's true severity in the first place) but it does establish exploitation in the wild of the CVE watchTowr's root-shell chain is believed to target.
No new patch action follows: CVE-2026-8452 is fixed in the same NetScaler 14.1-72.61 / 13.1-63.18 (13.1-37.272 on the FIPS/NDcPP train) release already recommended for CVE-2026-8451, so an estate that completed that upgrade is already remediated against both. Any appliance still unpatched, or whose upgrade was deferred on the assumption that CVE-2026-8452 was availability-only, should now be treated as having a confirmed unauthenticated remote-code-execution exposure under active exploitation rather than a theoretical one, and the compromise-assessment guidance already carried in this entry's actions applies with the same urgency to CVE-2026-8452 as to CVE-2026-8451.
Sources6
Revision history
- Published 2026-07-01-af9e697d
- Update 2026-08-15T0412Z-intel
watchTowr published a full exploitation chain on 2026-08-14 for a NetScaler ADC/Gateway heap overflow in SAML signature canonicalization, reaching a root shell pre-authentication, a bug whose public CVE description amounts to a "Memory Overflow". watchTowr believes but cannot confirm it is CVE-2026-8452, and NCSC-CH calls the analysis "likely related" to it. Both it and the sibling CVE-2026-8451 were fixed in the same June/July release; NCSC-CH has carried CVE-2026-8451 as actively exploited with a public proof of concept since 3 July, which this pipeline's original entry recorded as unconfirmed.
Changed: actions affected_products cves evidence regions sectors sources tags techniques body
- Update 2026-08-28T0409Z-intel
CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog on 2026-08-26, and ENISA's EU Vulnerability Database mirrors the same exploitedSince date. This is the first authoritative confirmation that CVE-2026-8452 specifically (not only its sibling CVE-2026-8451) is under active exploitation, resolving the uncertainty the prior update flagged when watchTowr said it "believes but cannot confirm" its pre-auth root-shell chain maps to this identifier. Both CVEs were already fixed in the same June/July release; no new patch action follows for an estate already remediated against CVE-2026-8451.
Changed: cves body
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.