CitrixBleed 2.0: CVE-2026-8451 NetScaler SAML IDP Memory Overread Under Active Exploitation — Threadlinqs Intelligence
As of 2026-07-19, CitrixBleed 2.0: CVE-2026-8451 NetScaler SAML IDP Memory Overread Under Active Exploitation is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1140 · Severity: CRITICAL · CVSS: 8.8 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-19 · revalidated 1× · latest source
Citrix disclosed CVE-2026-8451 on 2026-06-30 (bulletin CTX696604), a pre-authentication out-of-bounds memory read in NetScaler ADC/Gateway's custom SAML AuthnRequest XML parser when the appliance is
CVE-2026-8451 is an out-of-bounds read (CWE-125) in the custom XML attribute parser Citrix NetScaler ADC and NetScaler Gateway use to process SAML AuthnRequest documents on appliances configured as a SAML Identity Provider (IdP). The parser's attribute-value tokenizer only terminates an unquoted attribute value when it encounters a NUL byte, a closing '>' character, or a matching quote — it does not treat whitespace or a newline as a terminator. An attacker who sends a bare `<samlp:AuthnRequest` tag padded with hundreds of spaces and no closing attribute or tag causes the parser to keep consuming bytes past the end of the intended buffer, reading into adjacent process heap memory. The overread bytes are embedded, base64-encoded, in the `NSC_TASS` response cookie (the same cookie field that legitimately carries the parsed `ID` and `AssertionConsumerServiceURL` values), giving an unauthenticated remote attacker a repeatable memory-disclosure primitive capable of leaking session tokens, SAML assertions, LDAP credentials, and internal IP addresses from process memory.
The vulnerability was discovered by watchTowr Labs researcher Aliz Hammond in late March 2026 while reproducing the earlier CVE-2026-3055 ('CitrixBleed 3') SAML IdP overread, and Hammond noted that 'memory management continues to appear fragile within Citrix NetScaler appliances, to the extent that even accidentally misconfiguring an appliance can lead to the disclosure of leaked memory.' Citrix disclosed CVE-2026-8451 on 2026-06-30 as part of security bulletin CTX696604, alongside five related NetScaler flaws (CVE-2026-8452 memory overflow/DoS, CVE-2026-8655 memory overread on Oracle-type load-balancer/DNS-proxy configurations, CVE-2026-10816 unauthenticated arbitrary file read, CVE-2026-10817 TCP-Timestamps-triggered overread, and CVE-2026-13474 an HTTP/2 'bomb' DoS). watchTowr Labs simultaneously published a public Detection Artifact Generator reproducing the exact overread pattern (a bare AuthnRequest tag padded with 476 spaces and a trailing newline).
Within less than 24 hours of disclosure, Lupovis decoy-sensor infrastructure detected a single actor operating from 146.70.139.154 (M247 Europe SRL, AS9009, Frankfurt, Germany) systematically validating targets before exploiting them: the actor probed Sensor A twice (404 responses), then Sensor B (404), then Sensor C, which returned a 200 — at which point the actor immediately delivered the full CVE-2026-8451 exploit payload matching watchTowr's published Detection Artifact Generator almost byte-for-byte. All requests carried the `python-requests/2.32.5` User-Agent, consistent with scripted, automated tooling rather than manual exploitation. As of the initial disclosure window CVE-2026-8451 had not yet been added to the CISA KEV catalog, mirroring the pattern seen with CVE-2026-3055 and the original CitrixBleed, where confirmed in-the-wild exploitation preceded formal KEV listing by weeks, leaving organizations that rely solely on KEV-driven patch prioritization exposed during the gap.
CVE-2026-8451 is the latest entry in a recurring NetScaler authentication-stack memory-disclosure lineage: the original CitrixBleed (CVE-2023-4966, 2023) was weaponized at scale by LockBit 3.0 ransomware affiliates against victims including a Boeing parts-distribution subsidiary and the U.S. branch of ICBC, with stolen session tokens shown to survive patching; CVE-2025-5777 ('CitrixBleed 2') and CVE-2025-6543/CVE-2025-7775 followed in 2025; and CVE-2026-3055 ('CitrixBleed 3', CVSS v4 9.3) introduced the SAML IdP and WS-Federation attack surface in March 2026 and was added to CISA KEV on 2026-03-30 after large-scale exploitation (later reported by Fortinet) via crafted requests to /saml/login (omitting AssertionConsumerServiceURL) and /wsfed/passive?wctx (empty wctx parameter). NetScaler ADC and Gateway appliances are commonly deployed at the network perimeter as VPN termination points, application-delivery controllers, and SAML-ba
Target sectors: government administration, financial services, health, technology, critical infrastructure, legal services, logistics and supply chain, aerospace and defense
Target regions: North America, Europe, Middle East, Global
Detections & IOCs
As of 2026-07-21, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-8451, T1595.002, T1590.005, T1588.006, T1588.005, T1583.003, T1190, T1133, T1212, T1552.001, T1539