# CVE-2026-8451: Citrix NetScaler - Memory Disclosure

> Live exploitation tracking for CVE-2026-8451 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-8451

## Key facts

- **Exploitation phase:** Active Exploitation. The vulnerability is actively exploited at scale across the internet, often via automated tools and large attack campaigns.
- **CVSS score:** 8.8
- **Public exploit available:** Yes
- **Affected products:** Citrix NetScaler
- **Weaknesses:** CWE-125 (Out-of-bounds Read)
- **Tags:** enterprise_software

## Description

Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP

## CrowdSec analysis

[CVE-2026-8451](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-8451) is a high-severity vulnerability in NetScaler ADC and NetScaler Gateway that arises from insufficient input validation when configured as a SAML IDP, leading to potential memory overread. This flaw could allow remote attackers to access sensitive memory contents, potentially exposing confidential information and increasing the risk of further attacks.

CrowdSec has been tracking this vulnerability and its exploits since 1st of July 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2026-8451 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting.
In addition, according to the CrowdSec network, attack volume against CVE-2026-8451 has dipped slightly compared to the previous week. Although still commonly targeted, the decline suggests a cooling-off period. Long-term relevance remains, but attention is waning.

Attackers exploit CVE-2026-8451 by sending specially crafted SAML authentication requests to the `/saml/login` endpoint on Citrix NetScaler appliances configured as a SAML IdP. Malformed or unquoted XML attribute values (such as `AssertionConsumerServiceURL=` or `ID=`) terminated with a newline or left unterminated can trigger a memory overread, causing the appliance to leak sensitive memory contents via the `NSC_TASS` cookie in the HTTP response.

## Timeline

- 2026-06-30: CVE Published. CVE-2026-8451 is published to NVD.
- 2026-07-01: Rule Released. CrowdSec releases a rule to detect CVE-2026-8451 exploitation attempts against the CrowdSec Network.
- 2026-07-02: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-8451 for the first time.

## References

- https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604
- https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-8451) follows observed exploitation activity for CVE-2026-8451. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
