PT-2026-53879 · Citrix · Netscaler Gateway+1
CVE-2026-8451
·
Published
2026-03-28
·
Updated
2026-08-27
CVSS v2.0
9.7
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
NetScaler ADC versions prior to 14.1-72.61
NetScaler Gateway versions prior to 14.1-72.61
NetScaler ADC versions prior to 13.1-63.18
NetScaler Gateway versions prior to 13.1-63.18
NetScaler ADC FIPS versions prior to 14.1-72.61 FIPS
NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.272
Description
Insufficient input validation in the custom SAML XML parser allows an unauthenticated remote attacker to trigger a memory overread when the device is configured as a SAML Identity Provider (IdP). By sending a specially crafted
SAMLRequest to the /saml/login endpoint—specifically an AuthnRequest where attributes like AssertionConsumerServiceURL or ID lack a closing quote and are followed by a newline—the parser reads past the input buffer. The leaked process memory, which may include sensitive data such as active session fragments, authentication tokens, and internal heap pointers, is returned to the attacker base64-encoded within the NSC TASS cookie of the HTTP 302 response. This issue can also be used to crash the nsppe() process, resulting in a denial-of-service. Real-world exploitation attempts were detected shortly after the patch release, and over 900 hosts with Citrix Gateway signatures were identified, with approximately 84% potentially affected.Recommendations
Update NetScaler ADC and Gateway to version 14.1-72.61.
Update NetScaler ADC and Gateway to version 13.1-63.18.
Update NetScaler ADC FIPS to version 14.1-72.61 FIPS.
Update NetScaler ADC FIPS and NDcPP to version 13.1-37.272.
Disable the SAML IdP functionality if it is not required.
Restrict network access to the appliance using a firewall or IP whitelist.
Rotate all secrets and tokens that may have been stored in memory.
Monitor
/var/log/ns.log for anomalous SAML/XML processing errors or unusual NSC TASS cookie values.Fix
LPE
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netscaler Adc
Netscaler Gateway