Citrix disclosed a critical memory overread vulnerability, identified as CVE-2026-8451, in its NetScaler ADC and Gateway devices on June 30, 2026. This vulnerability affects devices configured as a SAML identity provider (IDP) and carries a CVSS score of 8.8.
CVE-2026-8451 results from insufficient input validation and allows a remote threat actor to send requests to the IDP appliance, triggering a memory overread that can leak sensitive data. Researchers at WatchTowr discovered the vulnerability in March and subsequently reported their findings to Citrix.
Lupovis reported a coordinated scanning campaign targeting NetScaler devices on July 1, less than 24 hours after the vulnerability's disclosure. The company confirmed that a single threat actor, associated with IP address 146.70.139.154, deployed an exploitation payload for CVE-2026-8451, and by July 3, Lupovis observed increased exploitation activity.
Xavier Bellekens, co-founder and CEO of Lupovis, stated that the observed activity was a specific exploit payload rather than generic scanning. He said, "This is the watchTowr overread variant designed to flood NetScaler's XML parser with whitespace, forcing it to read past the buffer boundary into adjacent memory." Bellekens added, "The structure matches the CVE-2026-8451 Detection Artifact Generator published by watchTowr on 30 June 2026."
Aviatrix issued a threat advisory regarding CVE-2026-8451, stating that a threat actor could exploit it to gain initial access to a NetScaler SAML IDP appliance. According to Aviatrix, leaked memory contents from the exploitation could be used to escalate privileges, facilitate lateral movement within a victim's network, and exfiltrate additional sensitive data. An Aviatrix spokesperson stated, "The disclosure underscores ongoing challenges in securing critical network infrastructure." The spokesperson also said, "Organizations relying on NetScaler appliances should promptly apply the provided patches and review their configurations to mitigate potential exploitation risks." The spokesperson noted that the company has not observed direct exploitation activity for this vulnerability.
Lupovis urged organizations to upgrade to NetScaler ADC and Gateway versions 14.1-72.61 or 13.1-63.18. Lupovis also recommended that customers disable the SAML IDP configuration on vulnerable appliances if patching is not possible. Organizations should review their SAML login activity starting June 30 for any suspicious behavior and block IP address 146.70.139.154, which is hosted on M247, a global VPN and hosting provider.
forum Comments (0)
No comments yet. Be the first to comment.