Citrix dropped patches for six vulnerabilities in NetScaler ADC and NetScaler Gateway this week. Some are nasty. And one of them is already being exploited in the wild.
The bugs range from file read flaws to denial-of-service conditions. Three of them carry a CVSS score of 8.8 — high on the severity scale. Here’s the rundown:
CVE-2026-8451 (CVSS 8.8) is an input validation bug in how NetScaler handles SAML authentication requests. It causes memory overreads when the appliance is configured as a SAML IDP. And it’s already getting hit — Lupovis spotted active exploitation from a Frankfurt-based IP within 24 hours of disclosure.
CVE-2026-8452 (CVSS 8.8) triggers memory overflow via Gateway or AAA virtual server configs, leading to DoS. CVE-2026-8655 (CVSS 8.8) does the same thing but through LB of type Oracle, DNS Proxy, or DNS recursive resolver deployments.
Then there’s CVE-2026-10816 (CVSS 7.7) — an unauthenticated arbitrary file read when certain management IPs are exposed. That one doesn’t even need authentication. CVE-2026-10817 (CVSS 6.9) is another memory overread via TCP timestamps. And CVE-2026-13474 (CVSS 8.7) lets attackers crash the box with malformed HTTP/2 requests.
Patches are out for versions 14.1-72.61, 13.1-63.18, and the FIPS/NDcPP builds. The HTTP/2 bug (CVE-2026-13474) needs a manual config parameter tweak on top of the upgrade if you’re not using strict HTTP profiles.
watchTowr Labs found CVE-2026-8451 while trying to reproduce an older Citrix bug (CVE-2026-3055). Same root cause — SAML parsing. Just a different angle. The exploit code is already public, and attackers are actively testing it.
If you’re running NetScaler, patch now. This one’s moving fast.
