CVE-2026-8451

Published Jun 30, 2026

Last updated 2 months ago

Overview

Description
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
Source
50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
NVD status
Analyzed
Products
netscaler_application_delivery_controller, netscaler_gateway

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.8
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-125

Social media

Hype score
Not currently trending
  1. The speed at which new CVEs are going from PoC to mass exploitation has changed. In June alone we saw three CVEs: CVE-2026-10520, CVE-2026-20253, and CVE-2026-8451 being exploited in the wild less that 24 hours after a PoC became available for them. All of them have had https

    @LupovisDefence

    14 Jul 2026

    305 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    2 Quotes

  2. ⚠️ Vulnerabilidades en productos Citrix ❗ CVE-2026-8655 ❗ CVE-2026-8452 ❗ CVE-2026-8451 ➡️ Más info: https://t.co/2dLfwsJi4C https://t.co/UwrkcXqHEb

    @CERTpy

    9 Jul 2026

    231 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Legacy exposure keeps paying off for attackers. CitrixBleed-style NetScaler flaw CVE-2026-8451 is already… Citrix patched CVE-2026-8451 in NetScaler SAML IdP deployments, and researchers saw exploit… 🔗 Read → https://t.co/n2P9vUQ3MF

    @fynn_JourX

    6 Jul 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. For defenders, citrixbleed-style netscaler flaw cve-2026-8451 is already being… should move fast. Citrix patched CVE-2026-8451 in NetScaler SAML IdP deployments, and researchers saw exploit… 🔗 Details → https://t.co/BoJ3brFLNe

    @SocXAInvaders

    6 Jul 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🛑 CitrixBleed-style NetScaler flaw CVE-2026-8451 is already being tested… Citrix patched CVE-2026-8451 in NetScaler SAML IdP deployments, and researchers saw exploit… 🔗 Details → https://t.co/TrNzhVZAYo

    @lucasverdan

    6 Jul 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. New vulnerabilities in Citrix NetScaler (CVE-2026-8451, memory leak) and Cisco UC Manager (CVE-2026-20230, SSRF to root) threaten data privacy & integrity in transit. Escalating geopolitical tensions amplify these critical risks. #Cybersecurity #News #Geopolitics

    @YourAnon_irc

    5 Jul 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Recent exploits: CVE-2026-8451 (Citrix NetScaler) allows memory disclosure. CVE-2026-48558 (SimpleHelp) is a critical auth bypass used for info stealer deployment. Both severely compromise data privacy & integrity in transit. #Cybersecurity #News #Vulnerabilities

    @YourAnon_irc

    5 Jul 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474 https://t.co/UGmoOer9KD #patchmanagement

    @eyalestrin

    4 Jul 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Citrix has recently released new updates to fix NetScaler ADC and NetScaler Gateway, where attackers would be able to conduct file reads and/or trigger a Denial-of-Service condition. These updates resolves the following CVEs: -> CVE-2026-8451 -> CVE-2026-8452 -> CVE-20

    @Leila97726926

    4 Jul 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Recent critical vulns: Citrix NetScaler (CVE-2026-8451) memory overread exposes sensitive data in transit. Gardyn IoT (CVE-2026-13768) key exposure enables RCE & network pivot. Immediate patching is crucial to safeguard privacy & integrity. #Cybersecurity #Vulnerabilities

    @YourAnon_irc

    3 Jul 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 【サイバーセキュリティ動向分析】 1. Citrix NetScalerの新脆弱性「CitrixBleed」の即時悪用 背景 Citrix(現Cloud Software Group)のNetScaler ADCおよびNetScaler Gatewayアプライアンスで発見された情報漏洩脆弱性(CVE-2026-8451、

    @kenebeii

    2 Jul 2026

    1101 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 6 high-severity Citrix NetScaler flaws - CVE-2026-8451 - CVE-2026-8452 - CVE-2026-8655 - CVE-2026-10816 - CVE-2026-10817 - CVE-2026-13474 All six stem from improper memory handling/input validation, enabling DoS and memory overflow. Fixes: - 14.1 → upgrade to 14.1-72.61

    @techepages

    1 Jul 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🚨 Citrix NetScaler Alert Citrix patched 6 NetScaler ADC/Gateway flaws that may allow file read, memory disclosure, and DoS. Key CVEs: CVE-2026-8451 CVE-2026-10816 CVE-2026-13474 Patch now and restrict management access. https://t.co/ShxoOY1gtb #CyberSecurity #Citrix #CVE #Vule

    @vulert_official

    1 Jul 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. #Citrix patches 6 high-severity NetScaler ADC/Gateway flaws: unauthenticated file read (CVE-2026-10816), SAML memory overread with recurring root cause (CVE-2026-8451), and HTTP/2 DoS (CVE-2026-13474). No active exploitation confirmed. #ThreatIntel https://t.co/pcwe3f5vkF

    @MeridianEU

    1 Jul 2026

    113 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨🚨🚨 NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474 https://t.co/5V1endcgNp

    @autumn_good_35

    1 Jul 2026

    620 Impressions

    0 Retweets

    3 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  16. 🚨🚨🚨@cloudsoftware has just issued a security bulletin for @NetScaler 🚨🚨🚨 Severity: *** HIGH *** CVE: CVE-2026-8451 / CVE-2026-8452 / CVE-2026-8655 / CVE-2026-10816 / CVE-2026-10817 / CVE-2026-13474 For more information: https://t.co/GsLEmIbEMS

    @jantytgat

    30 Jun 2026

    139 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations