A new pre-auth memory overread vulnerability, CVE-2026-8451 (CVSS 8.8), has been disclosed in Citrix NetScaler ADC and Gateway appliances configured as SAML Identity Providers. The flaw resides in the custom XML parser handling SAML AuthnRequest messages, where unquoted attribute values terminated by newlines cause the parser to read beyond the buffer boundaries. This leaked memory, which may include sensitive data or pointers, is returned to the attacker via the NSC_TASS cookie, and the issue can also be triggered to crash the nsppe process.
Memory Overread
3 posts
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2) A second memory overread vulnerability has been identified in Citrix NetScaler appliances under CVE-2026-3055, affecting the '/wsfed/passive?wctx' endpoint. By sending a specially crafted GET request with an empty 'wctx' parameter, attackers can force the appliance to leak sensitive memory, including administrative session IDs, via the 'NSC_TASS' cookie. Active in-the-wild exploitation has been observed since late March.
Vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway The NCSC has issued an alert regarding two vulnerabilities in customer-managed Citrix NetScaler ADC and Gateway appliances. CVE-2026-3055 allows for a memory overread in SAML IDP configurations, while CVE-2026-4368 causes user session mixups via a race condition in Gateway or AAA virtual server configurations. Immediate patching is strongly recommended.