CVE-2026-8451: Citrix NetScaler Vulnerability Leaks Memory  | eSecurity Planet

CVE-2026-8451: Citrix NetScaler Vulnerability Leaks Memory  | eSecurity Planet

By Ken Underhill
Publication Date: 2026-06-30 21:17:00

watchTowr researchers have discovered a vulnerability in Citrix NetScaler that can allow unauthenticated attackers to read portions of process memory from internet-facing appliances.  

The flaw affects NetScaler ADC and Gateway appliances configured as SAML identity providers (IdPs). 

In its security advisory, Citrix described the vulnerability as “insufficient input validation leading to memory overread” and assigned it a CVSS score of 8.8.  

Key Takeaways of CVE-2026-8451

  • CVE-2026-8451 is a pre-authentication memory disclosure vulnerability affecting Citrix NetScaler ADC and Gateway appliances configured as SAML identity providers.
  • The vulnerability allows specially crafted SAML requests to trigger an out-of-bounds memory read, potentially exposing sensitive process memory.
  • Researchers demonstrated that malformed requests could also crash the vulnerable process, creating a potential denial-of-service (DoS) condition. 

How CVE-2026-8451 Affects Citrix NetScaler…