By Elias Virtanen
Publication Date: 2026-08-09 20:18:00
Citrix pushed an emergency fix for its NetScaler ADC and NetScaler Gateway appliances on June 30, 2025, closing a hole that attackers started probing within roughly 24 hours of disclosure. The bug, tracked as CVE-2026-8451, carries a CVSS score of 8.8 and lets an unauthenticated attacker pull fragments of an appliance’s own memory, including live session cookies, out of any NetScaler box configured as a SAML identity provider. Researchers at watchTowr Labs, who found the flaw, titled their technical write-up “CitrixBleed to Infinity and Beyond,” a nod to the fact that this is not the first time, the second time, or even the third time NetScaler’s session-handling code has leaked sensitive data onto the open internet.

