CitrixBleed-ing Again? NetScaler Vulnerability Under Attack

Citrix’s NetScaler Vulnerability Under Attack Just Days After Patch Release

In a worrying turn of events, attackers have wasted no time targeting a recently discovered memory disclosure flaw in Citrix’s NetScaler products. The vulnerability, designated as CVE-2026-8451, was disclosed and patched by Citrix on June 30, but it appears that threat actors are already exploiting the weakness to gain access to sensitive corporate information.

The high-severity flaw affects Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices configured as a Security Assertion Markup Language (SAML) identity provider. When exploited, CVE-2026-8451 allows an attacker to send malicious requests to the IDP appliance, triggering a memory overread that leaks sensitive data. This is similar to the infamous “CitrixBleed” flaw (CVE 2023-4966), which was widely exploited after its disclosure in late 2023.

Researchers at WatchTowr discovered CVE-2026-8451 in March and reported their findings to Citrix, along with a proof-of-concept exploit. The vulnerability’s technical details were published on the same day as Citrix’s patch release. However, it appears that threat actors have been quick to capitalize on this knowledge, with at least one vendor reporting attacks against the latest NetScaler vulnerability.

Cybersecurity vendor Lupovis has reported a coordinated scanning campaign targeting NetScaler devices, which began just hours after the proof-of-concept exploit was published. According to Lupovis’s analysis, a single threat actor deployed an exploitation payload for CVE-2026-8451, using a malicious IP address hosted on M247, a global VPN and hosting provider commonly associated with opportunistic scanning campaigns.

Xavier Bellekens, co-founder and CEO of Lupovis, emphasized that the observed activity was not generic scanning but rather a specific exploit payload designed to target CVE-2026-8451. He noted that the threat activity matched the WatchTowr PoC, which suggests that attackers are actively exploiting this vulnerability.

The risks posed by CVE-2026-8451 are significant, as threat actors could use the memory-disclosure flaw to gain initial access to a NetScaler SAML IDP appliance and escalate privileges, move laterally in a victim’s network, and exfiltrate additional sensitive data. Cloud security vendor Aviatrix has issued a threat advisory urging organizations to promptly apply patches and review their configurations to mitigate potential exploitation risks.

In light of this development, it is essential for NetScaler users to take immediate action to protect themselves against CVE-2026-8451. This includes applying the provided patches, reviewing device configurations, and implementing robust security measures to prevent lateral movement and data exfiltration.


Source: Dark Reading — 2026-07-06