Another NetScaler security vulnerability in the vein of the infamous "CitrixBleed" flaw has come under attack, which could leak risky corporate information. Citrix on June 30 took the wraps off CVE-2026-8451, the memory overread vulnerability in the company's Netscaler product line that received a CVSS score of 8.8. The high-severity flaw affects Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices that are configured as a SAML identity provider (IDP). CVE-2026-8451 is caused by insufficient input validation, which allows a remote threat actor to send requests to the IDP appliance and trigger a memory overread that leaks sensitive data. Experts have noted the flaw is reminiscent of CitrixBleed (CVE 2023-4966), a critical zero-day vulnerability that came under widespread exploitation following its disclosure in late 2023. And like CitrixBleed and its successors, CVE-2026-8451 has also attracted the attention of threat actors. At least one vendor has reported attacks against the latest NetScaler vulnerability, following the publication of a proof-of-concept (PoC) exploit. Researchers at WatchTowr discovered CVE-2026-8451 in March and reported their findings to Citrix. WatchTowr Labs published full technical details of the flaw, which XML parser, and a PoC exploit on the same day Citrix disclosed and patched the flaw. The following day, cybersecurity vendor Lupovis reported a coordinated scanning campaign targeting NetScaler devices that began les...
CitrixBleed-ing Again? NetScaler Vulnerability Under Attack
Dark Reading
·Rob Wright
·Published Jul 6, 2026
·Updated
Affected Software
2 affected components
Citrix NetScaler Application Delivery Controller (ADC)=14.1-72.61, =13.1-63.18
Citrix NetScaler Gateway=14.1-72.61, =13.1-63.18
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a new security vulnerability in the Citrix NetScaler product line that is currently being exploited.
2
What is the nature of the vulnerability mentioned in the article?
The vulnerability, identified as CVE-2026-8451, is a memory overread flaw that could lead to the leakage of sensitive corporate information.
3
When was the vulnerability officially disclosed by Citrix?
The vulnerability was disclosed by Citrix on June 30, 2026.
4
What products are affected by the CVE-2026-8451 vulnerability?
The affected products include Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway.
5
Is this vulnerability actively being exploited?
Yes, the article indicates that the vulnerability has been marked as exploited and is part of the KEV list as of July 8, 2026.