Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
8.8
CVE-2026-8451KEVEXPLOITEDPATCHED
citrix · netscaler_application_delivery_controller

Insufficient input validation leading to memory overread

Description

The bug is described as an out-of-bounds read issue affecting NetScaler appliances configured as SAML IDP and leading to memory disclosure. It was discovered in NetScaler’s XML parser, which did not terminate unquoted XML attribute values if they were followed by a newline character. Because of the flaw, the parser would read past the intended buffer, and NetScaler would return memory contents in the NSC_TASS cookie in an HTTP response.

Affected Products

VendorProductVersions
citrixnetscaler_application_delivery_controller14.1, 13.1, 14.1 FIPs, 13.1 FIPS and NDcPP, 14.1, 13.1, 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS, 13.1-37.272

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
citrixnetscalercert_advisory90%
citrixnetscaler_gatewaycve_cpe95%

References

  • https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604

Related News (11 articles)

Tier D
The Hacker News3d ago
Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
→ No new info (linked only)
Tier E
Hacker News47d ago
CVE-2026-8451: Citrix NetScaler SAML Memory Overread
→ No new info (linked only)
Tier B
CCCS Canada52d ago
AL26-016 - Vulnerability impacting Citrix NetScaler CVE-2026-8451
→ No new info (linked only)
Tier D
SecurityWeek52d ago
New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure
→ No new info (linked only)
Tier B
BSI Advisories53d ago
[NEU] [hoch] Citrix Systems NetScaler ADC und Gateway: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
The Hacker News54d ago
Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
→ No new info (linked only)
Tier B
CERT-FR54d ago
Multiples vulnérabilités dans les produits Citrix (01 juillet 2026)
→ No new info (linked only)
Tier E
Reddit r/cybersecurity54d ago
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) - watchTowr Labs
→ No new info (linked only)
Tier E
Reddit r/netsec54d ago
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) - watchTowr Labs
→ No new info (linked only)
Tier B
CCCS Canada54d ago
Citrix security advisory (AV26-645)
→ No new info (linked only)
Tier C
VulDB54d ago
CVE-2026-8451 | Citrix NetScaler ADC/NetScaler Gateway buffer overflow (CTX696604)
→ No new info (linked only)
CVSS 3.18.8 CRITICAL
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
14.1-72.61
CWECWE-125, CWE-20
PublishedJun 30, 2026
Last enriched52d agov5
Tags
CVE-2026-8451CVE-2026-8452CVE-2026-8655CVE-2026-10816CVE-2026-10817CVE-2026-13474
Trending Score89
Source articles11
Independent9
Info Completeness12/14
Missing: epss, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-19490
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
Trending: 53
HIGHCVE-2026-8452EXPKEV
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
Trending: 46
NONECVE-2026-19489
CVE-2026-19489: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 thr
Trending: 40
NONECVE-2026-18751
Citrix Workspace App for Mac Security Bulletin for CVE-2026-18751
Trending: 20
NONECVE-2026-53565
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 30, 2026
Added to CISA KEV
Jun 30, 2026
Discovered by ZDM
Jun 30, 2026
Actively Exploited
Jun 30, 2026
Exploit Available
Jun 30, 2026
Patch Available
Jun 30, 2026
Updated: description, severity, activelyExploited
Jun 30, 2026
Updated: cvssEstimate, cweIds, tags
Jul 1, 2026
Updated: description, exploitAvailable, iocs
Jul 2, 2026
Updated: affectedVersions, patchAvailable, tags
Jul 2, 2026

Version History

v5
Last enriched 52d ago
v5Tier B52d ago

Updated product to include NetScaler Gateway, added new affected versions and fixed version numbers, and included additional CVE tags.

affectedVersionspatchAvailabletags
via CCCS Canada
v4Tier D52d ago

Updated description with technical details about the out-of-bounds read issue and added information on active exploitation and related IP addresses.

descriptionexploitAvailableiocs
via SecurityWeek
v3Tier D54d ago

Updated description with new details, added CVSS score of 8.8, and included new CWE ID CWE-20.

cvssEstimatecweIdstags
via The Hacker News
v2Tier C54d ago

Updated severity to CRITICAL, changed exploit availability to false, and provided a more detailed description of the vulnerability.

descriptionseverityactivelyExploited
via VulDB
v154d ago

Initial creation