CVE-2026-8452 in Citrix NetScaler: SAML parsing overflow leads to pre-auth RCE
CVE-2026-8452 in NetScaler ADC and Gateway (14.1 before 14.1-72.61 and 13.1 before 13.1-63.18, including FIPS and NDcPP) lets an unauthenticated attacker achieve remote code execution via a SAML parsing overflow. CVSS is 8.8, and CISA added the flaw to its Known Exploited Vulnerabilities catalog with a 29 August 2026 remediation deadline.
- Affected: NetScaler ADC and Gateway 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18
- CVSS 8.8: buffer overflow in the nsppe process yields pre-auth RCE
- CISA added CVE-2026-8452 to KEV on 26 August, patch due 29 August
- Web shells named x.php and z.php were found on compromised appliances
Read next
Security