NetScaler’s 4th Bleed Flaw Exploited in 24 Hours [2026]

Citrix pushed an emergency fix for its NetScaler ADC and NetScaler Gateway appliances on June 30, 2025, closing a hole that attackers started probing within roughly 24 hours of disclosure. The bug, tracked as CVE-2026-8451, carries a CVSS score of 8.8 and lets an unauthenticated attacker pull fragments of an appliance’s own memory, including live session cookies, out of any NetScaler box configured as a SAML identity provider. Researchers at watchTowr Labs, who found the flaw, titled their technical write-up “CitrixBleed to Infinity and Beyond,” a nod to the fact that this is not the first time, the second time, or even the third time NetScaler’s session-handling code has leaked sensitive data onto the open internet.

Since October 2023, Citrix’s flagship application-delivery appliance has now been the subject of four separate disclosure events tied to memory-disclosure or session-hijacking bugs in roughly the same corner of its codebase. Each one drew a high or critical severity score. Each one could hand an attacker a live, authenticated session without a username, a password, or a second factor. For the security teams who run NetScaler at the edge of banks, hospitals, government agencies, and thousands of mid-size enterprises, the June 2026 patch was not just another Tuesday-afternoon update. It was the fourth fire drill in three years, and this time attackers didn’t wait long to show up.

Google · Preferred Sources

Don't miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

What CVE-2026-8451 Actually Is

Citrix classifies CVE-2026-8451 as a pre-authentication memory overread, catalogued under CWE-125, sitting inside the SAML XML parser that NetScaler ADC and NetScaler Gateway use whenever an administrator configures the appliance as a SAML identity provider. In practice, that means a device sitting at the network edge, often the same box handling single sign-on for VPN or web-app logins, can be tricked into reading past the boundary of a memory buffer and echoing whatever it finds back to the attacker.

The affected builds, according to Citrix’s advisory (KB article CTX696604), are NetScaler ADC and Gateway 14.1 before build 14.1-72.61, 13.1 before build 13.1-63.18, and the FIPS and NDcPP-certified variants of both branches. Only appliances that customers manage themselves fall inside the blast radius. NetScaler instances that Citrix operates as a managed cloud service sit outside it, according to the Canadian Centre for Cyber Security’s advisory on the bug. The NVD entry for CVE-2026-8451 and a vulnerability-database writeup from SentinelOne both confirm the same root cause: insufficient input validation in how the appliance parses SAML authentication requests.

Inside the Exploit: The SAML AuthnRequest Path

The attack pattern for this entire family of NetScaler bugs starts the same way. “The attacker crafts an HTTP POST (or GET redirect-binding) to /saml/login containing a base64-encoded SAMLRequest XML,” Picus Security’s research team explained in its breakdown of a closely related pair of NetScaler bugs disclosed earlier in 2026. For CVE-2026-8451, a malformed SAML authentication request sent to that same login endpoint causes the appliance’s XML attribute parser to read outside its allocated buffer. Whatever sits in adjacent memory, potentially session tokens, authentication cookies, or fragments of other users’ traffic, can end up reflected back to the attacker inside the appliance’s own response.

That is the same basic mechanism that made the original 2023 CitrixBleed so damaging: a device built to protect a network instead leaks the keys to it. A stolen session cookie lets an attacker skip the login page entirely, multi-factor prompt included, and walk in as an already-authenticated user. No password guessing, no phishing email, no malware required.

24 Hours: How Fast Attackers Moved, and Who Found the Bug First

watchTowr researcher Aliz Hammond did not set out to find CVE-2026-8451. Hammond was reproducing a different, already-disclosed bug, CVE-2026-3055, the memory-overread half of a pair Citrix had published on March 23, 2025, when the research trail led to a second, distinct flaw sitting in the same SAML-parsing code. Citrix assigned it CVE-2026-8451 and shipped a fix on June 30, 2026.

Lupovis, a security firm that runs internet-facing deception infrastructure, observed exploitation attempts against the flaw within roughly 24 hours of disclosure. That turnaround has become close to routine for any NetScaler bug that touches session handling: attackers have learned that Citrix advisories are worth reverse-engineering fast, because the payoff, a working pre-auth session hijack against thousands of internet-facing appliances, tends to arrive within days of the patch notes going live.

The CitrixBleed Lineage: Four Disclosures, Three Years

Security teams have started using a single nickname, CitrixBleed, for this entire category of NetScaler bugs, borrowed from the original 2023 flaw. It’s a useful shorthand, but it undersells how often Citrix has had to run the same fire drill. Four separate disclosure events, covering five distinct CVEs, have hit the same SAML and session-handling territory since October 2023.

DisclosureCVE(s)DateCVSSKey Detail
CitrixBleedCVE-2023-4966Oct 10, 20239.4Zero-day exploited since Aug 2023; used by LockBit 3.0 affiliates
CitrixBleed 2CVE-2025-5777Jun 17, 20259.3Added to CISA KEV Jul 10, 2025; ~70,000 exposed instances (Censys)
CitrixBleed 3CVE-2026-3055 + CVE-2026-4368Mar 23, 20269.3 / 7.7Memory overread plus a session-mixup race condition, disclosed together
SAML overread (this story)CVE-2026-8451Jun 30, 20268.8Found while researchers reproduced CVE-2026-3055; exploited in ~24 hours

2023: The Original CitrixBleed and the LockBit Connection

CVE-2023-4966 is the bug that started the naming convention. Citrix rated it 9.4 on the CVSS scale and released a patch on October 10, 2023, but the flaw had already been under active, undetected exploitation since August of that year. “Citrix has advised that there is no workaround for this vulnerability and strongly recommends patching the affected software immediately,” Palo Alto Networks’ Unit 42 threat research team wrote in its brief on the flaw.

LockBit 3.0 ransomware affiliates seized on the bug for initial access, using leaked session data to bypass multi-factor authentication and hijack legitimate user sessions, according to government advisories issued at the time. The original CitrixBleed became one of the defining ransomware-enablement stories of 2023, and it set the template that every subsequent NetScaler disclosure would be measured against.

2025: CitrixBleed 2 and 70,000 Exposed Appliances

Citrix disclosed CVE-2025-5777, quickly nicknamed CitrixBleed 2, on June 17, 2025, with a CVSS score of 7.4.3. “CVE-2025-5777 is an out-of-bounds read vulnerability stemming from insufficient input validation in the NetScaler ADC and Gateway products,” according to Splunk’s security research team. Threat-intelligence firm GreyNoise recorded exploitation attempts beginning within days of disclosure, ahead of a public proof-of-concept that Akamai says surfaced on July 4, 2025. CISA added the bug to its Known Exploited Vulnerabilities catalog on July 10, 2025, confirming that exploitation was no longer theoretical.

Internet-scanning firm Censys counted close to 70,000 NetScaler Gateway and ADC instances still reachable from the open internet at the time, and threat-tracking service CrowdSec logged 254 distinct IP addresses actively attempting exploitation. Citrix’s guidance didn’t stop at patching. “In addition to Citrix’s recommendation to terminate all active ICA and PCoIP sessions, Arctic Wolf advises running additional commands to terminate RDP, AAA, and Load Balancing (LB) persistent sessions once all NetScaler appliances in the HA pair or cluster have been upgraded to the fixed builds,” Arctic Wolf’s incident-response team wrote in its follow-up guidance, underlining a point that would matter again a year later: patching alone doesn’t evict an attacker who already grabbed a valid session token.

March 2026: CitrixBleed 3 Sets the Stage

Nine months later, Citrix disclosed two more NetScaler bugs in a single bulletin. CVE-2026-3055, rated 9.3, was another memory overread tied to SAML identity-provider configurations, essentially the same fault class as CitrixBleed and CitrixBleed 2. CVE-2026-4368, rated 7.7, was a different animal: a race condition that could cause session mix-ups between users on Gateway or AAA virtual servers, limited to a narrower set of builds around version 14.1-66.54. Researchers quickly grouped the pair under the label CitrixBleed 3.

That March bulletin turned out to matter beyond its own patch cycle. It was the CVE that Aliz Hammond was reproducing three months later when the work surfaced an entirely separate bug in the same SAML code, the one that became CVE-2026-8451. One disclosure led directly to the next.

Why NetScaler’s SAML Code Keeps Failing

Four bugs in the same neighborhood of code over three years is not a coincidence of bad luck. SAML is an XML-based protocol, and parsing XML safely, at wire speed, on a device sitting pre-authentication at the internet edge, is one of the harder problems in appliance security. A single memory-safety mistake in that parser can produce several distinct, individually patchable bugs rather than one clean fix, which is consistent with what Citrix has actually shipped: a new CVE roughly every eight to nine months since 2023, each one closing one crack while leaving the surrounding wall standing.

The pattern also reflects a broader shift in how attackers get into networks. Exploiting a software flaw overtook stolen credentials as the leading way attackers gained initial access in 2026, accounting for roughly 31% of breaches, according to Verizon’s annual Data Breach Investigations Report. Edge appliances like NetScaler, precisely because they sit exposed to the internet by design and hold the keys to everything behind them, have become the preferred door. A Cloud Security Alliance research note on CVE-2026-8451 makes a similar point: appliances that combine authentication and network access in one box carry outsized risk precisely because a single memory bug can compromise both at once.

There’s also a structural reason patching hasn’t ended the cycle. NetScaler’s core is written in C for performance reasons, the same language choice that makes memory-safety bugs like out-of-bounds reads possible in the first place. Rewriting a two-decade-old XML parser in a memory-safe language would likely cost Citrix engineering months of regression testing against a customer base that runs the appliance in thousands of different configurations. Shipping a narrow patch for each newly discovered overread is faster and cheaper in the short term, but it treats the symptom rather than the parser design that keeps producing new instances of the same bug class. Until that changes, security teams should expect the CitrixBleed lineage to keep growing rather than close out with CVE-2026-8451.

Who’s Exposed and What Patching Actually Requires

Exposure is narrower than the headline CVSS score might suggest. Only customer-managed NetScaler ADC and Gateway appliances configured to act as a SAML identity provider are vulnerable, per Citrix’s own advisory. Appliances used purely as load balancers or ICA proxies, without SAML IdP functionality turned on, are not affected by this particular bug. That said, SAML-based single sign-on is a common configuration for exactly the kind of mid-size and large enterprises that rely on NetScaler for VPN and remote-access duty, which keeps the practical exposure wide even if the technical trigger condition is narrow.

NetScaler’s customer base skews toward organizations that can least afford downtime or a public breach: regional banks, hospital networks, insurers, and government agencies that adopted the appliance years ago for Citrix Virtual Apps and Desktops delivery, then layered SAML-based SSO on top as remote work expanded. Many of those environments run change-control processes that stretch a same-day emergency patch into a week-long approval cycle, which is exactly the gap attackers are counting on when they start probing within 24 hours of disclosure.

Beyond the Patch: Session Invalidation

The lesson from CitrixBleed 2 applies directly here. If an attacker captured a valid session cookie before an appliance was patched, upgrading the software does not automatically log that attacker out. Administrators need to check current NetScaler build numbers against the fixed versions, then treat any pre-patch session as potentially compromised.

show ns version
# Compare the reported build against the fixed versions:
#   NetScaler ADC / Gateway 14.1  -> 14.1-72.61 or later
#   NetScaler ADC / Gateway 13.1  -> 13.1-63.18 or later
#   NetScaler ADC FIPS            -> 14.1-72.61 FIPS or later
#   NetScaler ADC FIPS and NDcPP  -> 13.1-37.272 or later

Edge Appliances Under Fire: The Competitive Landscape

NetScaler is not the only edge appliance that has had a rough 2026. Comparing severity and exploitation speed across recent perimeter-device disclosures shows how compressed the window between patch and exploit has become industry-wide, and how the SAML/session-handling bug class fits into a bigger pattern of edge devices as the soft target of choice.

Vendor / ProductCVE(s)CVSSTime to ExploitationStatus
Citrix NetScaler (SAML IdP)CVE-2026-84518.8~24 hoursPatched Jun 30, 2026
Citrix NetScaler (CitrixBleed 3)CVE-2026-3055 / CVE-2026-43689.3 / 7.7Not publicly detailedPatched Mar 23, 2026
Citrix NetScaler (CitrixBleed 2)CVE-2025-57779.3Days after disclosureAdded to CISA KEV Jul 10, 2025
SonicWall SMA appliancesSee tech-insider.org coverage10.0~22 daysPatched, 2026
Adobe ColdFusionSee tech-insider.org coverage10.0~2 hoursPatched, 2026

The through-line is speed. Where organizations once had weeks to patch before mass exploitation began, the gap between a CVE going public and working exploit code hitting the internet has shrunk to hours in several 2026 cases. That compression is a big part of why zero-trust network access vendors keep pitching NetScaler and other appliance-based VPN customers on migration, a debate covered in tech-insider.org’s comparison of Zscaler, Palo Alto, and Cloudflare’s SASE platforms.

Market Impact: Patch Fatigue and a Vulnerability Management Boom

Cloud Software Group, the private entity that owns Citrix and NetScaler since Vista Equity Partners and Evergreen Coast Capital merged Citrix with TIBCO Software in 2022, has no public stock ticker. That means there’s no share price to watch move on disclosure day, unlike a breach at a publicly traded company. The cost of a fourth NetScaler fire drill in three years shows up somewhere else instead: in the hours security teams spend on emergency patch cycles, in cyber-insurance underwriting questionnaires that increasingly ask how fast a customer patches edge appliances, and in budget that shifts toward continuous exposure scanning rather than calendar-based patch management.

That budget shift is measurable in the vulnerability-management market itself. Enterprise buyers comparing platforms like those in tech-insider.org’s Tenable, Qualys, and Rapid7 pricing comparison increasingly cite exactly this kind of repeat-offender pattern, a single appliance vendor issuing critical CVEs on an eight-to-nine-month cadence, as justification for continuous scanning contracts over point-in-time audits.

The Cyber Insurance Angle

Insurers that write ransomware coverage have grown increasingly specific about edge-device patch cadence in their applications, largely because LockBit’s 2023 CitrixBleed campaign turned into a wave of claims. A repeat pattern at the same vendor gives underwriters a concrete data point to price into 2027 renewals, particularly for policyholders who confirm they still run NetScaler as a SAML identity provider.

What Happens Next: Five Predictions

  • CISA KEV listing is likely within weeks. CVE-2025-5777 was added to the Known Exploited Vulnerabilities catalog roughly three weeks after disclosure once active exploitation was confirmed; a similar timeline looks likely here given Lupovis already logged exploitation attempts within 24 hours.
  • Ransomware affiliates will test stolen sessions. Given LockBit’s 2023 playbook and the copycat groups that followed, expect stolen NetScaler session data from this disclosure to surface in access-broker markets within the current patch cycle.
  • More enterprises will move SAML off the appliance. Expect accelerated migration of identity-provider duties from NetScaler onto dedicated platforms like Okta or Microsoft Entra ID, treating the appliance as a network gateway only rather than an authentication endpoint.
  • Vulnerability-management vendors will use this as a sales hook. Expect Tenable, Qualys, Rapid7, and rivals to cite the NetScaler pattern, alongside 2026’s SonicWall and Adobe ColdFusion incidents, in pitches for continuous exposure management over periodic scanning.
  • At least one more NetScaler SAML or session bug surfaces before year-end. Four distinct disclosures in the same code path within three years, with researchers now actively fuzzing that exact parser, makes a fifth disclosure before 2027 a reasonable bet rather than a stretch.

How to Protect Your Organization Right Now

  • Patch all customer-managed NetScaler ADC and Gateway appliances to the fixed builds (14.1-72.61 or later, 13.1-63.18 or later, or the matching FIPS/NDcPP builds) immediately.
  • Confirm whether SAML IdP functionality is actually in use. If it isn’t needed, disable it to remove the attack surface entirely.
  • Terminate and invalidate all active ICA, PCoIP, RDP, AAA, and load-balancing persistent sessions after patching, following the same guidance security vendors issued for CitrixBleed 2.
  • Rotate credentials and secrets that may have transited SAML assertions on the appliance during the exposure window.
  • Review access logs for malformed SAMLRequest payloads or unusual traffic to the /saml/login endpoint predating the patch.
  • Restrict network-level access to SAML endpoints to known identity-provider traffic where your architecture allows it.

Frequently Asked Questions

What is CVE-2026-8451?
CVE-2026-8451 is a pre-authentication memory overread vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML identity provider. It carries a CVSS score of 8.8 and can expose session cookies and other memory contents to an unauthenticated attacker. Citrix patched it on June 30, 2026.

Is CVE-2026-8451 the same bug as CitrixBleed?
No. CVE-2026-8451 is a distinct vulnerability from the original 2023 CitrixBleed (CVE-2023-4966), but it belongs to the same broad family of NetScaler memory-disclosure bugs, which is why researchers and administrators group them under the same informal nickname.

Which NetScaler versions are affected by CVE-2026-8451?
NetScaler ADC and Gateway 14.1 before build 14.1-72.61, 13.1 before build 13.1-63.18, and the FIPS and NDcPP-certified variants of both branches, when configured as a SAML identity provider.

How is this different from CitrixBleed 2 and CitrixBleed 3?
CitrixBleed 2 (CVE-2025-5777) and the CitrixBleed 3 pair (CVE-2026-3055 and CVE-2026-4368) are separate, previously patched vulnerabilities in the same general code area. CVE-2026-8451 was actually discovered while a researcher was reproducing CVE-2026-3055, but it is a distinct flaw with its own CVE identifier and its own fix.

Who discovered CVE-2026-8451?
watchTowr Labs researcher Aliz Hammond found the flaw while reproducing an earlier NetScaler bug, CVE-2026-3055, and reported it to Citrix, which assigned the CVE-2026-8451 identifier.

Does patching alone fix an active compromise?
No. Security vendors that responded to CitrixBleed 2 in 2025 stressed that patching closes the hole going forward but does not invalidate session tokens an attacker may have already captured. Administrators need to terminate active sessions and rotate exposed credentials after upgrading.

Is Citrix or Cloud Software Group publicly traded?
No. Cloud Software Group, the parent company formed when Vista Equity Partners and Evergreen Coast Capital merged Citrix with TIBCO Software in 2022, remains privately held with no public stock ticker as of 2026.

Has CVE-2026-8451 been added to CISA’s Known Exploited Vulnerabilities catalog?
Citrix’s predecessor bug, CVE-2025-5777, was added to the CISA KEV catalog roughly three weeks after disclosure once active exploitation was confirmed. Administrators should treat CVE-2026-8451 with the same urgency regardless of its current KEV status and patch on Citrix’s published timeline rather than waiting for a federal mandate.

Related Coverage

Elias Virtanen

Elias Virtanen

Cybersecurity Analyst

Elias Virtanen is the Cybersecurity Analyst at Tech Insider, bringing hands-on expertise from his background in penetration testing and security consulting. He previously worked as a security researcher at F-Secure in Helsinki, where he focused on threat intelligence and vulnerability disclosure. Elias covers ransomware trends, zero-trust architecture, and the evolving regulatory landscape including NIS2 and the EU Cyber Resilience Act. He holds a CISSP certification and an MSc in Information Security from Aalto University.

View all articles