Citrix released security updates for NetScaler ADC and NetScaler Gateway to fix six vulnerabilities that could expose sensitive memory, crash devices, or allow unauthorized file access. The fixes cover CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, another medium-severity out-of-bounds read issue, and the NetScaler-specific HTTP/2 Bomb CVE-2026-13474; affected releases include 14.1-72.61 and 13.1-63.18, with FIPS and NDcPP builds also updated. WatchTowr says CVE-2026-8451 is a CitrixBleed-style memory disclosure bug tied to the XML parser and exploitable when NetScaler is configured as a Security Assertion Markup Language identity provider.
Why it matters: Organizations running self-managed NetScaler systems should treat this as a prompt patching issue because one flaw can leak memory and may help attackers chain toward full appliance compromise. Admins should update affected versions quickly and verify whether exposed features such as Security Assertion Markup Language identity provider mode are enabled.
Ionut Arghire
2026.07.02
95% relevant
This article directly updates the same CVE-2026-8451 NetScaler event by adding that attackers began probing and exploiting the flaw within 24 hours of disclosure, with observed payloads matching the public watchTowr detection artefact and targeting SAML IdP endpoints.
Ionut Arghire
2026.07.01
100% relevant
The article establishes a distinct NetScaler patch event beyond the broader HTTP/2 Bomb story by introducing Citrix-specific CVEs, affected product versions, and a separate high-severity CitrixBleed-style information disclosure flaw.
← Back to all stories