Threat reportVulnerabilityTL-2026-1078

CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest Memory Disclosure (CVE-2026-8451) Exploited Within 24 Hours of Disclosure

criticalACTIVE

CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest (TL-2026-1078), also tracked as CitrixBleed 3, is a critical-severity software vulnerability scored CVSS 8.8, first published 2026-07-02. It has no confirmed attribution, affects Citrix NetScaler ADC, references 10 CVEs (CVE-2026-8451, CVE-2026-8452, CVE-2026-8655), maps to 16 MITRE ATT&CK techniques (T1005, T1046, T1083), and is covered by 9 detection rules and 20 indicators of compromise.

CVSS
8.8/10Critical
CVEs
10Referenced vulnerabilities
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-1078

Threat ID
TL-2026-1078
Also known as
CitrixBleed 3, CitrixBleed To Infinity And Beyond
Severity
CRITICAL
CVSS
8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, legal, manufacturing, critical-infrastructure, education
Target regions
North America, Europe, Asia-Pacific, Global
Detection rules
9
Indicators of compromise
20

Malware and tooling in CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest

Malware and tooling: watchTowr-vs-Netscaler-CVE-2026-8451.py

How CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest works

A pre-authentication out-of-bounds read (CVSS 8.8) in NetScaler ADC/Gateway's custom SAML XML parser fails to terminate unquoted AuthnRequest attribute values on whitespace/newlines, causing an over-read of adjacent process memory that is echoed back to the attacker in the NSC_TASS cookie. A single threat actor began opportunistic, unauthenticated scanning and exploitation against the unauthenticated /saml/login endpoint within 24 hours of public disclosure, continuing the CitrixBleed lineage's pattern of rapid mass exploitation against edge infrastructure.

CVE-2026-8451 is a high-severity (CVSS 4.0: 8.8) memory-disclosure vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances configured as SAML Identity Providers, disclosed by Citrix on 2026-06-30 via advisory CTX696604 alongside five related CVEs (CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, CVE-2026-13474). The flaw was discovered by watchTowr Labs researcher Aliz Hammond in late March 2026 while reproducing a separate NetScaler vulnerability, CVE-2026-3055.

The root cause lies in NetScaler's decision to implement a custom, non-standard XML parser for SAML AuthnRequest documents rather than a vetted library. The parser's attribute-value tokenizer terminates unquoted values only when it encounters a null byte, a closing angle bracket ('>'), or a matching quote character -- it does not treat whitespace or newline characters as terminators, and it lacks bounds checking against the allocated input buffer. An attacker can submit a malformed, base64-encoded SAMLRequest to the unauthenticated /saml/login endpoint containing an unterminated opening <samlp:AuthnRequest> tag with an attribute such as AssertionConsumerServiceURL left blank, unquoted, and followed by a newline instead of a closing quote. The lenient tag-closure logic also allows a <saml:Issuer> element to be supplied outside the AuthnRequest element itself. Together these parser leniencies force the attribute-value reader to walk past the end of the intended input buffer and into adjacent heap memory, byte by byte, until it happens to encounter a terminator character.

The over-read bytes are captured as the (spoofed) attribute value and are subsequently embedded by NetScaler into the NSC_TASS authentication cookie returned to the client. Decoding the base64 cookie reveals raw process memory content -- watchTowr researchers confirmed genuine memory disclosure (rather than null-padding) by observing recognizable heap fill patterns (0xdeadbeef) and plausible pointer-like values (e.g., 0xa10ca7ed) in leaked output. Because the read walks byte-by-byte until any of a narrow set of terminators appears, single requests generally leak small, precisely-bounded memory fragments rather than the multi-kilobyte leaks characteristic of the earlier CVE-2026-3055 variant -- but repeated requests allow an attacker to harvest session tokens, internal pointers, and other sensitive appliance memory over time. A minimized, malformed variant of the same payload (a bare, unterminated <samlp:AuthnRequest ID= element with no closing tag) reliably crashes the nsppe worker process, giving attackers a low-cost, unauthenticated denial-of-service primitive against the same code path.

This places CVE-2026-8451 squarely in the CitrixBleed lineage that began with CVE-2023-4966 (the original CitrixBleed, CVSS 9.4, exploited at scale by LockBit 3.0 ransomware affiliates against Boeing, ICBC, Allen & Overy, and DP World via HTTP Host-header manipulation to leak AAA session cookies and hijack authenticated sessions without credentials or MFA) and continuing through CVE-2025-5777, CVE-2025-12101, and CVE-2026-3055. Each variant has independently demonstrated that NetScaler's custom XML/HTTP parsing layers are a recurring, systemic source of pre-auth memory disclosure in edge/VPN-gateway infrastructure -- a device class that is internet-facing by design and therefore an especially attractive initial-access vector for ransomware affiliates and APT groups alike.

Within 24 hours of the 2026-06-30 public disclosure and patch release, a single actor operating from 146.70.139.154 (M247 Europe SRL, AS9009, Frankfurt/Romania-registered hosting) began opportunistic, unauthenticated scanning and exploitation attempts against the /saml/login endpoint using a python-requests/2.32.5 automated client, sending crafted <samlp:AuthnRequest> payloads with 400+ space-padded attribute values consistent with reproduction of the public watchTowr research and/or its companion Detection Artefact Generator tooling. AS9009/M247 is a long-standing Eastern European hosting network repeatedly implicated in scanning, C2, and APT staging activity (including Cloud Atlas campaigns and malicious npm package staging), consistent with its use here as disposable, rapidly-provisioned scanning infrastructure rather than attributed to a named, tracked threat actor at this time.

Organizations running NetScaler ADC/Gateway as a SAML Identity Provider on versions before 14.1-72.61 or 13.1-63.18 (including FIPS/NDcPP variants) should treat this as an active, time-critical exposure: patch immediately, rotate all session-related secrets and certificates as a precaution against undetected historical exploitation, and hunt for the payload and cookie patterns documented below.

MITRE ATT&CK techniques used in TL-2026-1078

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Discovery

T1046 Network Service Discovery; T1083 File and Directory Discovery; T1518 Software Discovery

Initial Access

T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Credential Access

T1212 Exploitation for Credential Access; T1539 Steal Web Session Cookie; T1606 Forge Web Credentials

Impact

T1486 Data Encrypted for Impact; T1499 Endpoint Denial of Service

lateral-movement

T1550 Use Alternate Authentication Material

Resource Development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

Reconnaissance

T1595 Active Scanning

Affected products and versions in CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest

  • Citrix — NetScaler ADC
    Vulnerable versions: 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS/NDcPP before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-63.18
    Fixed in: 14.1-72.61; 13.1-63.18
  • Citrix — NetScaler Gateway
    Vulnerable versions: 14.1 before 14.1-72.61; 13.1 before 13.1-63.18
    Fixed in: 14.1-72.61; 13.1-63.18

Remediation for CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest

Patches

  • NetScaler ADC and Gateway 14.1-72.61 and later
  • NetScaler ADC and Gateway 13.1-63.18 and later
  • Citrix Security Bulletin CTX696604 (covers CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, CVE-2026-13474)

Immediate actions

  • Patch NetScaler ADC/Gateway to 14.1-72.61 or later (14.1 branch) or 13.1-63.18 or later (13.1 branch), including FIPS and NDcPP variants
  • If patching cannot occur immediately, disable SAML IdP functionality on the appliance or restrict access to /saml/login at the network layer (WAF/ACL) to trusted source IPs only
  • Block or heavily monitor traffic from 146.70.139.154 and the broader AS9009 (M247 Europe SRL) netblock at the perimeter
  • Deploy or run watchTowr's Detection Artefact Generator (watchTowr-vs-Netscaler-CVE-2026-8451.py) against internet-facing appliances to confirm exposure prior to patching
  • Terminate and invalidate all active NetScaler AAA/SAML sessions and rotate NSC_TASS-related session secrets after patching

Workarounds

  • Disable SAML Identity Provider configuration on the NetScaler appliance until patched
  • Restrict inbound access to /saml/login to known, trusted source IP ranges via ACL or WAF rule
  • Deploy a reverse-proxy or WAF rule rejecting SAMLRequest payloads containing unterminated tags, unquoted attribute values, or embedded newline characters within XML attribute positions

Longer-term hardening

  • Rotate TLS certificates and any secrets/keys that may reside in NetScaler process memory as a precaution against undetected historical memory disclosure
  • Deploy network-layer monitoring/IDS signatures for malformed SAMLRequest payloads (unterminated AuthnRequest tags, unquoted attribute values followed by newlines)
  • Implement centralized logging and alerting on NetScaler nsppe process crashes as an early-warning indicator of exploitation attempts
  • Establish an accelerated patch cadence for internet-facing NetScaler/Citrix edge infrastructure given the repeated CitrixBleed-lineage disclosure pattern
  • Review and reduce use of custom, non-standard XML/HTTP parsers in favor of vetted, hardened parsing libraries where architecturally feasible

CVEs associated with CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest

CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, CVE-2026-13474, CVE-2023-4966, CVE-2025-5777, CVE-2025-12101, CVE-2026-3055

Weaknesses (CWE) in CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest

CWE-125, CWE-119, CWE-20, CWE-287

Timeline of CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest

  • watchTowr Labs researcher Aliz Hammond discovers the flaw while reproducing CVE-2026-3055 and notifies Citrix; Citrix acknowledges receipt.
  • First of multiple follow-up exchanges between watchTowr and Citrix as Citrix confirms fix development is underway.
  • Citrix informs watchTowr of a planned 2026-06-29 public disclosure and patch date.
  • Citrix requests a short delay of a few days to the disclosure date; watchTowr accepts.
  • Citrix ships fixed NetScaler ADC/Gateway builds 14.1-72.61 and 13.1-63.18 (including FIPS/NDcPP variants) addressing CVE-2026-8451 and five related CVEs.
  • Citrix publishes Security Bulletin CTX696604 and patched NetScaler builds (14.1-72.61, 13.1-63.18); watchTowr Labs publishes its technical writeup and releases the Detection Artefact Generator tool.
  • Trade press (CyberScoop, The Hacker News, GBHackers, eSecurity Planet) publishes coverage framing the flaw within the CitrixBleed lineage and urging urgent patching.
  • Within roughly 24 hours of disclosure, opportunistic unauthenticated scanning/exploitation attempts are observed from 146.70.139.154 (AS9009, M247 Europe SRL) against the /saml/login endpoint using a python-requests/2.32.5 client and crafted, space-padded AuthnRequest payloads.
  • TL-Intel Harness HUNT phase surfaces active-exploitation reporting via Cyber Security News and opens threat TL-2026-1078.
  • Cyber Security Agency of Singapore (CSA) publishes alert AL-2026-082 covering the NetScaler vulnerabilities.

Sources cited for CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest

Detection coverage for TL-2026-1078

As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1078 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats