Citrix NetScaler Flaw Enables Unauthenticated Data Leakage

Citrix NetScaler Flaw Enables Unauthenticated Data Leakage

By Rabia Noureen
Publication Date: 2026-07-08 13:34:00

Key Takeaways:

  • CVE-2026-8451 affects Citrix NetScaler systems configured as SAML identity providers.
  • Attackers can trigger memory disclosure without valid credentials.
  • Organizations should update affected NetScaler versions and review authentication logs.

Cybersecurity researchers have warned of a new “CitrixBleed To Infinity And Beyond” vulnerability that could expose sensitive corporate data from vulnerable Citrix NetScaler appliances. This critical flaw can be exploited without authentication, which makes it a significant threat to enterprise environments.

WatchTowr researchers discovered the CVE-2026-8451 vulnerability in March and responsibly disclosed it to Citrix. On June 30, Citrix publicly disclosed the flaw and assigned it a CVSS score of 8.8. The same day, WatchTowr released technical details and a proof-of-concept (PoC) exploit demonstrating the vulnerability.

How can the…