Successful exploitation of CVE-2026-8451 could allow unauthenticated memory disclosure in NetScaler appliances when configured as a SAML IDP
Successful exploitation of CVE-2026-8451 could allow unauthenticated memory disclosure in NetScaler appliances when configured as a SAML IDP
The following platforms are known to be affected:
Proof-of-Concept Exploit
Security researchers have released a public proof-of-concept exploit for CVE-2026-8451.
Memory leakage vulnerabilities in Citrix NetScaler, dubbed "CitrixBleed", have been weaponised rapidly following the release of a public proof-of-concept exploit in the past.
The NHS England National CSOC assesses exploitation as highly likely.
Citrix has released a security advisory to address a high severity vulnerability in NetScaler ADC and NetScaler Gateway. Successful exploitation could allow an unauthenticated attacker to achieve memory disclosure in NetScaler appliances when configured as a SAML IDP.
Affected organisations are encouraged to review Citrix advisory CTX696604 and apply the relevant update as soon as possible.
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP.
Last edited: 1 July 2026 2:19 pm
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
