By Guru Baran
Publication Date: 2026-07-02 16:38:00
A newly disclosed CitrixBleed-class vulnerability in Citrix NetScaler appliances came under active exploitation less than a day after public disclosure, with decoy infrastructure operator Lupovis confirming a coordinated scanning-and-exploitation campaign across three separate sensor deployments.
Within 24 hours of Citrix publishing advisory CTX696604 and watchTowr Labs releasing a Detection Artifact Generator for CVE-2026-8451, Lupovis decoy infrastructure detected a coordinated scanning campaign targeting NetScaler appliances configured as SAML Identity Providers.
A threat actor operating from IP 146.70.139[.]154 targeted three separate Lupovis sensor deployments in a five-hour window on 30 June to 1 July 2026, ultimately delivering a confirmed CVE-2026-8451 exploitation payload.
Notably, this activity is not yet reflected in the CISA Known Exploited Vulnerabilities (KEV) catalog, echoing a pattern seen in prior CitrixBleed incidents where in-the-wild exploitation…



