PT-2026-53879 · Citrix · Netscaler Gateway+1

CVE-2026-8451

·

Published

2026-03-28

·

Updated

2026-08-27

CVSS v2.0

9.7

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:C
Name of the Vulnerable Software and Affected Versions NetScaler ADC versions prior to 14.1-72.61 NetScaler Gateway versions prior to 14.1-72.61 NetScaler ADC versions prior to 13.1-63.18 NetScaler Gateway versions prior to 13.1-63.18 NetScaler ADC FIPS versions prior to 14.1-72.61 FIPS NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.272
Description Insufficient input validation in the custom SAML XML parser allows an unauthenticated remote attacker to trigger a memory overread when the device is configured as a SAML Identity Provider (IdP). By sending a specially crafted SAMLRequest to the /saml/login endpoint—specifically an AuthnRequest where attributes like AssertionConsumerServiceURL or ID lack a closing quote and are followed by a newline—the parser reads past the input buffer. The leaked process memory, which may include sensitive data such as active session fragments, authentication tokens, and internal heap pointers, is returned to the attacker base64-encoded within the NSC TASS cookie of the HTTP 302 response. This issue can also be used to crash the nsppe() process, resulting in a denial-of-service. Real-world exploitation attempts were detected shortly after the patch release, and over 900 hosts with Citrix Gateway signatures were identified, with approximately 84% potentially affected.
Recommendations Update NetScaler ADC and Gateway to version 14.1-72.61. Update NetScaler ADC and Gateway to version 13.1-63.18. Update NetScaler ADC FIPS to version 14.1-72.61 FIPS. Update NetScaler ADC FIPS and NDcPP to version 13.1-37.272. Disable the SAML IdP functionality if it is not required. Restrict network access to the appliance using a firewall or IP whitelist. Rotate all secrets and tokens that may have been stored in memory. Monitor /var/log/ns.log for anomalous SAML/XML processing errors or unusual NSC TASS cookie values.

Fix

LPE

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08971
CVE-2026-8451

Affected Products

Netscaler Adc
Netscaler Gateway