CitrixBleed is back: a NetScaler flaw that leaks memory — and with it, the session tokens that unlock your network

CVE-2026-8451 makes NetScaler ADC and Gateway over-read memory when configured as a SAML identity provider, potentially spilling session tokens.…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

The flaw: insufficient input validation → memory over-read (CWE-125) in NetScaler ADC/Gateway.

What you need to know

Trigger: the device configured as a SAML identity provider (IDP).

What you need to know

The danger: leaked memory can include session tokens — enabling authentication bypass (the CitrixBleed pattern).

What you need to know

Affected: NetScaler ADC/Gateway 13.1 (before 13.1-63.18), 14.1 (before 14.1-72.61), and FIPS/NDcPP builds.

What you need to know

Fix: update to the patched NetScaler builds immediately; it's unauthenticated and network-reachable.

Aliteq

Read the full story

CitrixBleed is back: a NetScaler flaw that leaks memory — and with it, the session tokens that unlock your network

Read the full story on Aliteq