# CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest Memory Disclosure (CVE-2026-8451) Exploited Within 24 Hours of Disclosure

> A pre-authentication out-of-bounds read (CVSS 8.8) in NetScaler ADC/Gateway's custom SAML XML parser fails to terminate unquoted AuthnRequest attribute values on whitespace/newlines, causing an over-read of adjacent process memory that is echoed back to the attacker in the NSC_TASS cookie. A single threat actor began opportunistic, unauthenticated scanning and exploitation against the unauthenticated /saml/login endpoint within 24 hours of public disclosure, continuing the CitrixBleed lineage's pattern of rapid mass exploitation against edge infrastructure.

- **Published:** 2026-07-02T00:00:00Z
- **Last reviewed:** 2026-07-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1078
- **ID:** TL-2026-1078
- **Severity:** CRITICAL (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, CVE-2026-13474, CVE-2023-4966, CVE-2025-5777, CVE-2025-12101, CVE-2026-3055

## Description

CVE-2026-8451 is a high-severity (CVSS 4.0: 8.8) memory-disclosure vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances configured as SAML Identity Providers, disclosed by Citrix on 2026-06-30 via advisory CTX696604 alongside five related CVEs (CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, CVE-2026-13474). The flaw was discovered by watchTowr Labs researcher Aliz Hammond in late March 2026 while reproducing a separate NetScaler vulnerability, CVE-2026-3055.

The root cause lies in NetScaler's decision to implement a custom, non-standard XML parser for SAML AuthnRequest documents rather than a vetted library. The parser's attribute-value tokenizer terminates unquoted values only when it encounters a null byte, a closing angle bracket ('>'), or a matching quote character -- it does not treat whitespace or newline characters as terminators, and it lacks bounds checking against the allocated input buffer. An attacker can submit a malformed, base64-encoded SAMLRequest to the unauthenticated /saml/login endpoint containing an unterminated opening <samlp:AuthnRequest> tag with an attribute such as AssertionConsumerServiceURL left blank, unquoted, and followed by a newline instead of a closing quote. The lenient tag-closure logic also allows a <saml:Issuer> element to be supplied outside the AuthnRequest element itself. Together these parser leniencies force the attribute-value reader to walk past the end of the intended input buffer and into adjacent heap memory, byte by byte, until it happens to encounter a terminator character.

The over-read bytes are captured as the (spoofed) attribute value and are subsequently embedded by NetScaler into the NSC_TASS authentication cookie returned to the client. Decoding the base64 cookie reveals raw process memory content -- watchTowr researchers confirmed genuine memory disclosure (rather than null-padding) by observing recognizable heap fill patterns (0xdeadbeef) and plausible pointer-like values (e.g., 0xa10ca7ed) in leaked output. Because the read walks byte-by-byte until any of a narrow set of terminators appears, single requests generally leak small, precisely-bounded memory fragments rather than the multi-kilobyte leaks characteristic of the earlier CVE-2026-3055 variant -- but repeated requests allow an attacker to harvest session tokens, internal pointers, and other sensitive appliance memory over time. A minimized, malformed variant of the same payload (a bare, unterminated <samlp:AuthnRequest ID= element with no closing tag) reliably crashes the nsppe worker process, giving attackers a low-cost, unauthenticated denial-of-service primitive against the same code path.

This places CVE-2026-8451 squarely in the CitrixBleed lineage that began with CVE-2023-4966 (the original CitrixBleed, CVSS 9.4, exploited at scale by LockBit 3.0 ransomware affiliates against Boeing, ICBC, Allen & Overy, and DP World via HTTP Host-header manipulation to leak AAA session cookies and hijack authenticated sessions without credentials or MFA) and continuing through CVE-2025-5777, CVE-2025-12101, and CVE-2026-3055. Each variant has independently demonstrated that NetScaler's custom XML/HTTP parsing layers are a recurring, systemic source of pre-auth memory disclosure in edge/VPN-gateway infrastructure -- a device class that is internet-facing by design and therefore an especially attractive initial-access vector for ransomware affiliates and APT groups alike.

Within 24 hours of the 2026-06-30 public disclosure and patch release, a single actor operating from 146.70.139.154 (M247 Europe SRL, AS9009, Frankfurt/Romania-registered hosting) began opportunistic, unauthenticated scanning and exploitation attempts against the /saml/login endpoint using a python-requests/2.32.5 automated client, sending crafted <samlp:AuthnRequest> payloads with 400+ space-padded attribute values consistent with reproduction of the public watchTowr research and/or its companion Detection Artefact Generator tooling. AS9009/M247 is a long-standing Eastern European hosting network repeatedly implicated in scanning, C2, and APT staging activity (including Cloud Atlas campaigns and malicious npm package staging), consistent with its use here as disposable, rapidly-provisioned scanning infrastructure rather than attributed to a named, tracked threat actor at this time.

Organizations running NetScaler ADC/Gateway as a SAML Identity Provider on versions before 14.1-72.61 or 13.1-63.18 (including FIPS/NDcPP variants) should treat this as an active, time-critical exposure: patch immediately, rotate all session-related secrets and certificates as a precaution against undetected historical exploitation, and hunt for the payload and cookie patterns documented below.

## MITRE ATT&CK

- T1595 Active Scanning
- T1583 Acquire Infrastructure
- T1588 Obtain Capabilities
- T1190 Exploit Public-Facing Application
- T1539 Steal Web Session Cookie
- T1606 Forge Web Credentials
- T1212 Exploitation for Credential Access
- T1518 Software Discovery
- T1550 Use Alternate Authentication Material
- T1210 Exploitation of Remote Services
- T1005 Data from Local System
- T1499 Endpoint Denial of Service
- T1486 Data Encrypted for Impact
- T1083 File and Directory Discovery
- T1046 Network Service Discovery
- T1213 Data from Information Repositories

## Sources

- [CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public Disclosure](https://cybersecuritynews.com/citrixbleed-vulnerability-exploited/)
- [CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)](https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/)
- [CVE-2026-8451: Citrix NetScaler Vulnerability Leaks Memory](https://www.esecurityplanet.com/threats/cve-2026-8451-citrix-netscaler-vulnerability-leaks-memory/)
- [Citrix patches a new NetScaler flaw with echoes of CitrixBleed](https://cyberscoop.com/citrix-netscaler-flaw-cve-2026-8451-citrixbleed/)
- [Multiple High-Severity Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-8451)](https://beazley.security/alerts-advisories/multiple-high-severity-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway-cve-2026-8451)
- [Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service](https://thehackernews.com/2026/07/citrix-patches-six-netscaler-flaws.html)
- [CVE-2026-8451 – Memory Overread / Sensitive Data Exposure – NetScaler ADC and NetScaler Gateway](https://www.ionix.io/threat-center/cve-2026-8451/)
- [Citrix NetScaler ADC and Gateway Flaws Let Attackers Trigger Memory Overread and Denial-of-Service](https://gbhackers.com/citrix-netscaler-adc-and-gateway-flaws/)
- [Multiple Vulnerabilities in NetScaler Products](https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-082/)
- [CVE-2026-8451 (Tenable CVE database)](https://www.tenable.com/cve/CVE-2026-8451)
- [Citrix Security Bulletin CTX696604](https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604)
- [#StopRansomware: LockBit 3.0 Ransomware Affiliates Exploit CVE-2023-4966 Citrix Bleed Vulnerability](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-325a)
- [CVE-2023-4966: LockBit Exploits Citrix Bleed in Ransomware Attacks](https://www.picussecurity.com/resource/blog/cve-2023-4966-lockbit-exploits-citrix-bleed-in-ransomware-attacks)
- [Guidance for Addressing Citrix NetScaler ADC and Gateway Vulnerability CVE-2023-4966, Citrix Bleed](https://www.cisa.gov/guidance-addressing-citrix-netscaler-adc-and-gateway-vulnerability-cve-2023-4966-citrix-bleed)
- [Inside Eastern Europe's C2 Sprawl: 3,900+ Servers, 302 Providers, One Host Doing Half the Work](https://hunt.io/blog/eastern-europe-malicious-infrastructure-report)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1078
