A new high-severity vulnerability, CVE-2026-8451, affecting NetScaler ADC and NetScaler Gateway appliances is under active exploitation. The flaw, which is being compared to the infamous CitrixBleed vulnerability, is an out-of-bounds read issue that can disclose sensitive information from the device's memory. With a CVSS score of 8.8 (High), the vulnerability was weaponized by threat actors less than 24 hours after its public disclosure on June 30, 2026. The rapid exploitation was fueled by the simultaneous release of patches by Citrix and a detailed technical write-up and proof-of-concept (PoC) by security firm watchTowr. Organizations using affected NetScaler appliances configured as a SAML identity provider (IDP) are urged to apply the patches immediately.
CVE-2026-8451 is an out-of-bounds read vulnerability that exists in the XML parser of NetScaler appliances. The flaw is triggered when the device is configured as a Security Assertion Markup Language (SAML) identity provider (IDP). Specifically, the parser incorrectly handles unquoted XML attribute values that are followed by a newline character. This causes the parser to read beyond the intended memory buffer.
An unauthenticated attacker can send a specially crafted request to a vulnerable appliance. In response, the device will return contents of its memory within the NSC_TASS cookie in an HTTP response. This leaked memory can contain sensitive information such as session cookies, credentials, and other confidential data, which could then be used to hijack legitimate user sessions and gain unauthorized access to the network.
The vulnerability affects the following products when they are configured as a SAML IDP:
Citrix has released patches to address this vulnerability, and administrators should consult the official Citrix security bulletin for the specific patched versions.
According to security firm Lupovis, scanning and exploitation activity began almost immediately after the vulnerability details were made public. The first scans were observed originating from an IP address in Frankfurt, Germany. The attackers appeared to be using a detection script based on the PoC released by watchTowr. The extremely short time between disclosure and exploitation (less than 24 hours) underscores a trend where threat actors have automated pipelines to monitor vulnerability disclosures, develop exploits, and launch attacks at scale.
The impact of exploiting CVE-2026-8451 can be severe:
The vulnerability's resemblance to CitrixBleed (CVE-2023-4966) is particularly concerning, as that flaw was widely exploited by ransomware groups and other threat actors to cause significant damage.
Security teams should hunt for the following patterns to identify exploitation attempts:
+/saml/loginNSC_TASS cookie in responseNSC_TASS cookie being returned in an HTTP response from the NetScaler device, as it contains the leaked memory content.NSC_TASS cookie that exceeds a normal size threshold. This aligns with D3FEND's Network Traffic Analysis.New details for CVE-2026-8451 include specific affected NetScaler versions, an observed attacker IP (146.70.139.154) from July 1, 2026, and an explicit workaround to disable SAML IdP functionality.
Further information regarding the actively exploited CVE-2026-8451 has emerged. Specific affected versions of NetScaler ADC and Gateway include 14.1 before 14.1-29.72, 13.1 before 13.1-55.39, and 13.0 before 13.0-94.25. An observed attacker IP address, 146.70.139.154 (Germany), was seen exploiting the vulnerability on July 1, 2026. As a critical workaround, administrators can disable the SAML IdP functionality if immediate patching is not possible. Post-patching, it is advised to hunt for compromise, rotate credentials, and invalidate active sessions.
New details on CVE-2026-8451 in NetScaler ADC/Gateway include specific affected versions, patched versions, and expanded impact on credentials and crypto keys. Immediate patching is critical.
The latest intelligence on CVE-2026-8451, the CitrixBleed-like flaw in NetScaler ADC and Gateway, now specifies affected versions: 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18. Citrix-managed cloud services are already patched. The impact assessment has been expanded to explicitly include the leakage of user credentials, password hashes, and cryptographic keys, in addition to session tokens, enabling attackers to bypass authentication and gain unauthorized access. Remediation now emphasizes upgrading to the specified patched versions, hunting for compromise, and rotating credentials as a critical follow-up step.
New details emerge on CVE-2026-8451 exploitation, including a detailed timeline, enhanced hunting hints, and advanced detection and mitigation strategies. Active attacks continue, reinforcing the urgent need for patching.
New intelligence provides a more granular timeline for CVE-2026-8451, detailing its discovery in March 2026 by WatchTowr, public disclosure and PoC release on June 30, and active exploitation observed by Lupovis on July 1. The update also includes expanded hunting hints, such as monitoring VPN/application logs and user geolocation patterns for session hijacking. Enhanced detection strategies now emphasize log analysis for IP/user agent mismatches, IDS/IPS signatures, and D3FEND techniques like Network Traffic Analysis and User Geolocation Logon Pattern Analysis. Mitigation advice is further refined, urging organizations to check SAML IDP configurations and assume compromise for unpatched systems. These details underscore the ongoing, critical threat posed by this vulnerability.
Citrix discloses CVE-2026-8451 and releases patches. watchTowr simultaneously publishes a technical PoC.
Lupovis reports observing active scanning and exploitation of the vulnerability, less than 24 hours after disclosure.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.