• News/
  • darkreading-20260706211742

CitrixBleed-ing Again? NetScaler Vulnerability Under Attack

Dark Reading
·
Rob Wright
·
Published Jul 6, 2026
·
Updated

Another NetScaler security vulnerability in the vein of the infamous "CitrixBleed" flaw has come under attack, which could leak risky corporate information. Citrix on June 30 took the wraps off CVE-2026-8451, the memory overread vulnerability in the company's Netscaler product line that received a CVSS score of 8.8. The high-severity flaw affects Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices that are configured as a SAML identity provider (IDP). CVE-2026-8451 is caused by insufficient input validation, which allows a remote threat actor to send requests to the IDP appliance and trigger a memory overread that leaks sensitive data. Experts have noted the flaw is reminiscent of CitrixBleed (CVE 2023-4966), a critical zero-day vulnerability that came under widespread exploitation following its disclosure in late 2023. And like CitrixBleed and its successors, CVE-2026-8451 has also attracted the attention of threat actors. At least one vendor has reported attacks against the latest NetScaler vulnerability, following the publication of a proof-of-concept (PoC) exploit. Researchers at WatchTowr discovered CVE-2026-8451 in March and reported their findings to Citrix. WatchTowr Labs published full technical details of the flaw, which XML parser, and a PoC exploit on the same day Citrix disclosed and patched the flaw. The following day, cybersecurity vendor Lupovis reported a coordinated scanning campaign targeting NetScaler devices that began les...

Read full article

Affected Software

2 affected components
Citrix NetScaler Application Delivery Controller (ADC)=14.1-72.61, =13.1-63.18
Citrix NetScaler Gateway=14.1-72.61, =13.1-63.18
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new security vulnerability in the Citrix NetScaler product line that is currently being exploited.

2

What is the nature of the vulnerability mentioned in the article?

The vulnerability, identified as CVE-2026-8451, is a memory overread flaw that could lead to the leakage of sensitive corporate information.

3

When was the vulnerability officially disclosed by Citrix?

The vulnerability was disclosed by Citrix on June 30, 2026.

4

What products are affected by the CVE-2026-8451 vulnerability?

The affected products include Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway.

5

Is this vulnerability actively being exploited?

Yes, the article indicates that the vulnerability has been marked as exploited and is part of the KEV list as of July 8, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203