🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

Citrix NetScaler Memory Overread Exploit Active (CVE-2026-8451) | MSSP Advisory

Critical🔴 KEV ALERTConfirmed
DateJuly 3, 2026
CVECVE-2026-8451, CVE-2023-4966, CVE-2026-3055
CVSS Score7.5
Affectednetscaler_application_delivery_controller, netscaler_gateway
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
Citrix has patched CVE-2026-8451, a memory overread vulnerability in NetScaler ADC and NetScaler Gateway appliances that allows unauthenticated attackers to send malformed requests and leak protected process memory data. The flaw requires the appliance to be configured as a SAML Identity Provider, a configuration that is not uncommon, and active exploitation attempts were observed on honeypot sensors within 24 hours of the patch release. The same patch cycle also addresses two high-severity memory overflow vulnerabilities (CVE-2026-8452 and CVE-2026-8655) that attackers can chain with the memory leak to bypass ASLR and achieve full device compromise.
⚠️Why It Matters for MSSPs
If you or any of your clients are running NetScaler ADC or NetScaler Gateway as a SAML IdP, those appliances are being actively probed right now, and an unpatched device sitting in front of a client network is your liability, not just theirs. The chaining risk is the part that should keep you up tonight: the memory leak alone may not hand attackers credentials, but paired with the overflow CVEs in the same patch batch, it becomes a path to full device takeover and everything behind it. If a client gets hit through a NetScaler you manage and you had not communicated this patch, that is a retention conversation you do not want to have.
Recommended Action
Audit every NetScaler ADC and NetScaler Gateway appliance in your stack and across all managed client environments within the next 24 hours, prioritize any configured as a SAML Identity Provider, and push the upgrade to versions 14.1-72.61, 13.1-63.18, or the applicable FIPS and NDcPP builds immediately, then run the watchTowr Python detection script against any appliance you cannot patch tonight to confirm exposure status before morning.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.