By Rabia Noureen
Publication Date: 2026-07-08 13:34:00
Key Takeaways:
- CVE-2026-8451 affects Citrix NetScaler systems configured as SAML identity providers.
- Attackers can trigger memory disclosure without valid credentials.
- Organizations should update affected NetScaler versions and review authentication logs.
Cybersecurity researchers have warned of a new “CitrixBleed To Infinity And Beyond” vulnerability that could expose sensitive corporate data from vulnerable Citrix NetScaler appliances. This critical flaw can be exploited without authentication, which makes it a significant threat to enterprise environments.
WatchTowr researchers discovered the CVE-2026-8451 vulnerability in March and responsibly disclosed it to Citrix. On June 30, Citrix publicly disclosed the flaw and assigned it a CVSS score of 8.8. The same day, WatchTowr released technical details and a proof-of-concept (PoC) exploit demonstrating the vulnerability.


