your Citrix login page can be hacked without anyone entering a password — patch it today

CVE-2026-8452 lets an attacker with zero credentials overflow a buffer inside NetScaler and run their own code — and Citrix's advisory was so thin…

Aliteq
Ravi Malhotra · Hardware Editor

The short version

CVE-2026-8452 is a pre-auth heap overflow in NetScaler ADC and Gateway, reachable with zero credentials when SAML is configured as SP or IdP.

The short version

CVSS 8.8. It was patched alongside five other CVEs (including CVE-2026-8451, a separate CitrixBleed-style memory overread) in Citrix's July 1, 2026 advisory.

The short version

Affected: NetScaler ADC/Gateway 14.1 before 14.1-72.61, and 13.1 before 13.1-63.18 (FIPS/NDcPP builds have their own fixed versions).

The short version

watchTowr Labs, the research team that first named CitrixBleed, found and reported it — and says Citrix's own advisory text was too vague to confirm the CVE number with certainty.

The short version

No confirmed in-the-wild exploitation as of publication, but NetScaler's exploitation history says that window closes fast once a public proof-of-concept lands.

Patch priority

If you run NetScaler with SAML configured anywhere, this is a today problem, not a this-sprint problem. The fix has existed for weeks; the only thing standing between an attacker and your appliance…

Aliteq

Read the full story

your Citrix login page can be hacked without anyone entering a password — patch it today

Read the full story on Aliteq